# Missing geo\_point field

**URL:** <https://discuss.elastic.co/t/missing-geo-point-field/257577>\
**Category:** Elastic Security\
**Tags:** elastic-agent\
**Created:** [December 3, 2020, 7:44pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577 "2020-12-03T19:44:02Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 3, 2020, 7:44pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/1 "2020-12-03T19:44:02Z")

</div>

Hi,

I'm experiencing this issue on a fresh ELK 7.10 installation. I just deployed the _Elastic-Agent_ with the only integration _Endpoint_ , not even _system_ . Is there a solution or workaround available or this is still under research?

[![geolocation1](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c2773597b619e9455a31a980193d8609dc247ed.png)](https://user-images.githubusercontent.com/63368223/101078928-d02caf80-3574-11eb-87be-d49a98956ba0.PNG)  
[![geolocation2](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a69aa52ff38d160425b247aa8894fc917db70eb.png)](https://user-images.githubusercontent.com/63368223/101078935-d28f0980-3574-11eb-8238-fc7f77161a7f.PNG)  
[![geolocation3](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c2f09803d8f301c5380bd776fbeb3571d89c23e.png)](https://user-images.githubusercontent.com/63368223/101078948-d4f16380-3574-11eb-9600-5f43ab1429e3.PNG)

Thank you

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 8, 2020, 3:55pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/2 "2020-12-08T15:55:48Z")

</div>

Hi,

Any update on this?

Thanks

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 9, 2020, 2:08pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/3 "2020-12-09T14:08:15Z")

</div>

I'm including the mappings, to help you with the troubleshooting

- `.ds-logs-elastic_agent.metricbeat-default-000001`  
[Mapping](https://pastebin.com/frFnMy44)
- `.ds-logs-elastic_agent.filebeat-default-000001`  
[Mapping](https://pastebin.com/zy7T0YbB)
- `.ds-logs-elastic_agent-default-000001`  
[Mapping](https://pastebin.com/rxjte25N)

---

<div class="post-metadata">

**Author:** ![EricDavisX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericdavisx/32/73456_2.png) [@EricDavisX](https://discuss.elastic.co/u/EricDavisX)\
**Post date:** [December 9, 2020, 9:03pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/4 "2020-12-09T21:03:38Z")

</div>

Hi, thanks for the ping back. I'm interested to confirm some questions that may be "too basic" or silly, but they would help build context.

- Are you using self-managed or cloud based stack?

- While you cite it was a 'fresh' deploy of 7.10 (which is helpful to know) was any data restored as part of the process, or upgraded and then migrated over to the 'fresh' install?

- Are there any old Beats running on any hosts pointing to this cluster?

We aren't sure yet why you are seeing this, I see some chatter from team on it internally. Hopefully more will be known and we can post back! Thanks for posting the mappings!

Thank you,  
Eric, a tester guy at Elastic

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 9, 2020, 9:58pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/5 "2020-12-09T21:58:38Z")

</div>

Hi,

Thank you for your interest on my report. Answering to your questions:

- This would be a "self-managed" stack

- The only beats shipping data to the stack are matching the stack version (7.10.0) and are also fresh installed. Just a couple of hosts are currently sending data to this new stack, so the data sources are controlled.

- I did import some saved objects in Kibana, from other stack running v7.9.2. Mostly dashboards and visualizations. Most of theses pulls data from `winlogbeat-*,` if this information helps somehow.  
All indexes are new. I did not import any from other stack.

- Finally, in the other stack I implemented a the `geo_ip` enrichment by following [this documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-geoip.html). I have not done so for current stack running v7.10.0. I wasn't sure if it was going to be necessary or not.

If you require more details, please let me know.

Thank you

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 14, 2020, 1:57pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/6 "2020-12-14T13:57:07Z")

</div>

Hi,

Any update about this issue?

Thank you

---

<div class="post-metadata">

**Author:** ![EricDavisX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericdavisx/32/73456_2.png) [@EricDavisX](https://discuss.elastic.co/u/EricDavisX)\
**Post date:** [December 14, 2020, 9:11pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/7 "2020-12-14T21:11:17Z")

</div>

> [@ManuelF](#):
>
> I did import some saved objects in Kibana, from other stack running v7.9.2. Mostly dashboards and visualizations. Most of theses pulls data from `winlogbeat-*,` if this information helps somehow.  
> All indexes are new. I did not import any from other stack.

Hi Manual, thank you for the good info and reply. I don't have much experience deep diving on this, but we are building good info to bring it to the Fleet team to review - what you posted is very helpful. I do have one more idea.

I do think the import of the Kibana Saved-Objects is impacting your usage. Fleet relies heavily on SO in Kibana in 7.10. It seems likely something from the geo\_ip setup done in 7.9.2 didn't get fully and correctly setup in 7.10 just by doing the Kibana Saved Objects import action.

From that, I can cite, if you _just_ want to get it working again, you could probably clone a new 7.10 and start fresh without importing the saved objects and it should work. If you just want to wipe ES and Kibana, that should do it. I don't know how to guide you to more surgically try to delete the problems and the impact from them.

If you are ok to re-set the cluster and work then that's your call, please let us know how it goes!

But if you want to follow thru further with the current cluster and assess deeper still, we could review what Saved Objects you have. If you desire, you can this doc [link](https://www.elastic.co/guide/en/kibana/current/managing-saved-objects.html#:~:text=To%20get%20started%2C%20open%20the,click%20Stack%20Management%20%3E%20Saved%20Objects.) and send us the capture for review.

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 14, 2020, 9:46pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/8 "2020-12-14T21:46:32Z")

</div>

Hi @EricDavisX,

Thank you for your help. Reset/rebuild the stack is not an option for me unfortunately. In fact this is a fresh ELK installation, because the last upgrade from v7.9.2 did not work as expected. The only thing I keep saving from the old version, are just the visualizations and dashboards, in which I spent a lot of time designing and building. Deploying a new stack from scratch it is also time consuming. Therefore It would be difficult for me to wipe out everything and start over one more time (perhaps when I switch over ELK 8, because it will introduce many deep changes).

On the other hand, none of the visualizations imported is reading data from Metricbeat, nor Filebeat, but from Winlogbeat. Winlogbeat was not mentioned in the errors. Do you still think it might be related?

Do you think I should try [this](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-geoip.html) first? Would it be OK to modify the configuration file generated by the Filebeat instance running under the Elastic-Agent to add the geoIP config line?: `C:\Program Files\Elastic\Agent\data\elastic-agent-1428d5\install\filebeat-7.10.0-windows-x86_64`

---

<div class="post-metadata">

**Author:** ![EricDavisX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericdavisx/32/73456_2.png) [@EricDavisX](https://discuss.elastic.co/u/EricDavisX)\
**Post date:** [December 14, 2020, 10:12pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/9 "2020-12-14T22:12:55Z")

</div>

Hi, I don't know that the Elastic Agent controlled Beats will pick up the config changes you make, I'm not sure - you can try it tho.

I fully understand the time to get a cluster up and that re-setting it isn't an option, it was a long shot I proposed if you had spare resources to help confirm it was the import of the saved objects that was negatively impacting. About that... I'm not sure of the recommended way to export / import data across clusters - the Fleet product being pre-GA we are still trying to make upgrades work. I'm sorry to hear the original 7.9.x to 7.10 upgrade didn't work.

Regards,  
Eric

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 14, 2020, 10:43pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/10 "2020-12-14T22:43:49Z")

</div>

Hi, one more time I really appreciate the time you are taking to help me on this. I don't think either that the Elastic Agent controlled Beats will pick up the config changes I make. I don't see any custom config to match my stack connection, so it may be using the connection config from Elastic-Agent in background.

I could try re-importing the objects in Kibana, but not build them from scratch. I can export them all and delete them after, then check Security and see if the error persist. Once the test have concluded I just have to import all objects one more time.

I'll try that tomorrow morning and let you know how it went.

Thank you

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 21, 2020, 10:10pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/11 "2020-12-21T22:10:54Z")

</div>

Hi @EricDavisX,

I removed all imported objects from my node and restarted ELK. The issue persist. My question is:

After you install ELK from scratch (clean installation, nothing more than ELK) do you need to enable or config anything so Security or Elastic Agent can collect geo location data?

What it looks like is that the geo-location data is not available.

Thank you

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 21, 2020, 11:13pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/12 "2020-12-21T23:13:42Z")

</div>

Is it safe If I delete index `.ds-logs-elastic_agent-default-000001`? Will this harm my ES, or ES will re-create the index?

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [December 28, 2020, 5:48pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/13 "2020-12-28T17:48:36Z")

</div>

@EricDavisX, Please I need to know if it is safe to remove index `.ds-logs-elastic_agent-default-000001` and if ES will re-create it. Perhaps this helps to fix the error.

Thank you

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [December 28, 2020, 9:00pm UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/14 "2020-12-28T21:00:49Z")

</div>

System indices start with a dot ( `.` ) like .kibana or .security and others, so you should be very careful not to delete these since it will break your cluster.

**However** , indices that use data streams also use a dot syntax (starting with `.ds*` ) these you can delete, so you can delete older ones if need be.

If you go into the console, and paste this, this will lists the indices and sort them via creation date.

```
GET _cat/indices?v&h=h,s,i,id,p,r,dc,dd,ss,creation.date.string&s=creation.date
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:19am UTC](https://discuss.elastic.co/t/missing-geo-point-field/257577/15 "2022-11-04T08:19:00Z")

</div>


