# Moved from 7.x to 8.x ... Maps stopped working

**URL:** <https://discuss.elastic.co/t/moved-from-7-x-to-8-x-maps-stopped-working/376112>\
**Category:** Logstash\
**Created:** [March 19, 2025, 9:58am UTC](https://discuss.elastic.co/t/moved-from-7-x-to-8-x-maps-stopped-working/376112 "2025-03-19T09:58:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexolivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexolivan/32/57425_2.png) [@alexolivan](https://discuss.elastic.co/u/alexolivan)\
**Post date:** [March 19, 2025, 9:58am UTC](https://discuss.elastic.co/t/moved-from-7-x-to-8-x-maps-stopped-working/376112/1 "2025-03-19T09:58:25Z")

</div>

Hi!

I'm really stuck with this new geo\_point stuff.  
I have also read about disabling ECS compatibility mode on my pipeline but... I would rather learn the propper way to do thing from now ownwards. So, this is the updated geoip pipeline lines that are (still) working:

```auto
		if [clientip] {
			geoip {
				source => "clientip"
				target => "source"
				#add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
				#add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
                add_field => ["[geoip][coordinates]", "%{[source][geo][location][lon]}" ]
                add_field => ["[geoip][coordinates]", "%{[source][geo][location][lat]}" ]
				id => "icecast2GeoIP"
			}
			mutate {
				convert => ["[geoip][coordinates]", "float" ]
				id => "icecast2GeoIPMutate"
			}
		}

```

I have noticed all my 'geo' information land now under source. field, including a pair of numeric 'lat' and 'lon' fields under source.geo.location.  
So far, so good...  
But my kibana maps find any useable geopoint data to use.

My guess is that I need to 'assemble' a geo\_point field here... I feel its close, since data is there on the documents, but I'm failing to figure out how.

Could anyone point me out the way to do that?

Thanks.  
Cheers.

Alejandro.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 19, 2025, 2:29pm UTC](https://discuss.elastic.co/t/moved-from-7-x-to-8-x-maps-stopped-working/376112/2 "2025-03-19T14:29:19Z")

</div>

> [@alexolivan](#):
>
> My guess is that I need to 'assemble' a geo\_point field here...

I don't think so. From what I can see the default ECS V8 template maps [source][geo][location] as a geo\_point. If it is not a geo\_point then you are probably not using that template.

[Take a look](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html) at your mapping and see what you need to change there. Note that changes to the template are only applied when a new index is created.

This is not something to fix in logstash. You don't need to worry about converting strings into floats -- elasticsearch will do that for you if it knows the field is a geo\_point.
