# Missing geoip.location

**URL:** <https://discuss.elastic.co/t/missing-geoip-location/241004>\
**Category:** Logstash\
**Created:** [July 13, 2020, 3:26pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004 "2020-07-13T15:26:37Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![brapnda23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brapnda23/32/71267_2.png) [@brapnda23](https://discuss.elastic.co/u/brapnda23)\
**Post date:** [July 13, 2020, 3:26pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/1 "2020-07-13T15:26:38Z")

</div>

New to ELK...My test ELK instance is 7.8.x.

I am using the below filter code for IIS Logs and it is working fine. I can see other geo fields but I don't see geoip.location as mentioned in [https://www.elastic.co/blog/geoip-in-the-elastic-stack](https://www.elastic.co/blog/geoip-in-the-elastic-stack). Anything else I should be doing to get the geoip.location?

```auto
filter {
  if "IIS" in [tags] {
    grok {
      match => { "message" => "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:S-SiteName} %{NOTSPACE:S-ComputerName} %{IPORHOST:S-IP} %{WORD:CS-Method} %{URIPATH:CS-URI-Stem} %{NOTSPACE:CS-URI-Query} %{NUMBER:S-Port} %{NOTSPACE:CS-Username} %{IPORHOST:C-IP} %{NOTSPACE:CS-Version} %{NOTSPACE:CS-UserAgent} %{NOTSPACE:CS-Cookie} %{NOTSPACE:CS-Referer} %{NOTSPACE:CS-Host} %{NUMBER:SC-Status} %{NUMBER:SC-SubStatus} %{NUMBER:SC-Win32-Status} %{NUMBER:SC-Bytes} %{NUMBER:CS-Bytes} %{NUMBER:Time-Taken}"}
    }
geoip { source => "C-IP"}
  }
}

```

 ![geoip.location.missing](https://us1.discourse-cdn.com/elastic/original/3X/3/9/3977fc1bb349dfe3c4c5a4e89909a6ac4b41d2b8.png)

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 13, 2020, 3:37pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/2 "2020-07-13T15:37:24Z")

</div>

I think I don't understand your question? Where are you missing the location? In your screenshot it is listed: `geoip.location.lat` and `geoip.location.lon`. Do you mean that is not listed as a geopoint data type? That would probably be because you didn't define it as a geo\_point in your mapping.

---

<div class="post-metadata">

**Author:** ![brapnda23](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brapnda23/32/71267_2.png) [@brapnda23](https://discuss.elastic.co/u/brapnda23)\
**Post date:** [July 13, 2020, 4:03pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/3 "2020-07-13T16:03:09Z")

</div>

That screenshot is from kibana discover. I thought geoip.location should be another filed over there along with .lat and .lon. Like the below screenshot from the above article.

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d1d9e10d9e7b8cd21480c743e6f0f7397ee07142.jpeg)

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 13, 2020, 4:13pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/4 "2020-07-13T16:13:10Z")

</div>

`geoip.location` is a field that consists of two values: `lat` and `lon`. To use it in the map visualization it has to be defined as the data type `geo_point` in the mapping of your index (the definition of the data types of all the fields in your index). This is shown in your tutorial in the section " **Mapping, for Maps**".

```
"geoip" : {
  "dynamic": true,
  "properties" : {
    ...
    "location" : { "type" : "geo_point" },
    ...
  }

```

If you are not using one of those default templates mentioned, you'll have to configure this data type yourself:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)

You can see the current mapping by querying `GET yourindex/_mapping`. To index your data with a different data type you'll have to reindex it in a new index with the correct settings because you can not change the mapping of a field once it has already been assigned a data type.

---

<div class="post-metadata">

**Author:** ![andrew.campbell](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@andrew.campbell](https://discuss.elastic.co/u/andrew.campbell)\
**Post date:** [July 15, 2020, 12:25am UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/5 "2020-07-15T00:25:25Z")

</div>

Hey Jenni, same issue for me. But I am not seeing how to deal with the mapping as I have the data coming from Logstash and when creating the Index Pattern, there is no way to change field mappings before the indexing happens. Or are you saying this is done in Logstash? I have indicies for each day's worth of logs and I see that these fields are mapped to a number instead of the geo\_point. I can change this in the Index Pattern after the fact and upload it (via Saved Objects), but that won't help with the current index as you mention. But, if I create a new index from Logstash, that new Index Pattern will be used and back at square one where the mapping is incorrect.

As a side comment, it seems odd that these values don't map to geo\_point out of the box as that is what they are used for...

Anyway, thank you!

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 15, 2020, 3:20am UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/6 "2020-07-15T03:20:47Z")

</div>

> [@andrew.campbell](#):
>
> there is no way to change field mappings before the indexing happens

That's exactly what index templates are for 🙂

> Templates are configured prior to index creation and then when an index is created either manually or through indexing a document, the template settings are used as a basis for creating the index

---

<div class="post-metadata">

**Author:** ![andrew.campbell](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@andrew.campbell](https://discuss.elastic.co/u/andrew.campbell)\
**Post date:** [July 15, 2020, 10:09pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/7 "2020-07-15T22:09:56Z")

</div>

OK, I've been able to setup the index template and the fields are now set to a type of geo\_point. But now i'm getting a parse error. geo\_point expected, but that is what is the configured type.

`:response=>{"index"=>{"_index"=>"colliers.com-prod-cd-2020.06.11", "_type"=>"_doc", "_id"=>"4Hp7VHMB5Vmbl9eI_mv9", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [geoip.location.lon] of type [geo_point]", "caused_by"=>{"type"=>"parse_exception", "reason"=>"geo_point expected"}`

This is the specific section of the template:  
` "latitude" : { "type" : "float" }, "location" : { "properties" : { "lat" : { "type" : "geo_point" }, "lon" : { "type" : "geo_point" } } }, "longitude" : { "type" : "float" },`

I originally had the full latitude and longitude fields set to geo\_point as well, and that also failed parsing.

What am I missing? thanks for your help with this!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 15, 2020, 10:20pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/8 "2020-07-15T22:20:51Z")

</div>

> [@andrew.campbell](#):
>
> "failed to parse field [geoip.location.lon] of type [geo\_point]"

If your template sets geoip.location.lon as a geo\_point then remove that. geoip.location should be a geo\_point.

---

<div class="post-metadata">

**Author:** ![andrew.campbell](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@andrew.campbell](https://discuss.elastic.co/u/andrew.campbell)\
**Post date:** [July 15, 2020, 11:11pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/9 "2020-07-15T23:11:54Z")

</div>

Thanks for the help all! Issue resolved...in a different way. I was unable to get the template working from the dev tools. I could request it and see that it was updated, but it wasn't being used to parse the logs. I ended up creating it via the gui to create an new index template and add the same json for the mappings. That worked and now I have the location type of geo\_point on the map 🙂

Still not sure why updating via the dev tools did not work and through the gui did. But, removing the .lat and .lon fields and setting only location did do the trick.

```
        "latitude": {
          "type": "float"
        },
        "location": {
          "type": "geo_point"
        },
        "longitude": {
          "type": "float"
        },

```

 ![2020-07-15_1610](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cb4f8427e9f98b0894d56cf54bcfdc200caa4a43.jpeg)

@brapnda23 I can show you the details tomorrow...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2020, 11:11pm UTC](https://discuss.elastic.co/t/missing-geoip-location/241004/10 "2020-08-12T23:11:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
