# No geoip points in kibana map

**URL:** <https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145>\
**Category:** Kibana\
**Tags:** maps\
**Created:** [September 11, 2022, 4:40pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145 "2022-09-11T16:40:34Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![SirStephanikus](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@SirStephanikus](https://discuss.elastic.co/u/SirStephanikus)\
**Post date:** [September 11, 2022, 4:40pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/1 "2022-09-11T16:40:34Z")

</div>

Hello everyone and welcome to another rooky question 😃

In a very simple logstash pipeline, I want to enter via stdin an ipv4 address and ship it to elasticsearch...than get the geoip location drawn on a map.

However...I get no results (and no error).  
Yes I read a lot..but I had no luck to solve it on my own.

What I did:  
In Elasticsearch, I created an index:

```auto
PUT testme
{
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "source": {
          "type": "ip"
        },
        "geoip": {
          "properties": {
            "location": {
              "type": "geo_point"
            }
          }
        }
      }
    }
  }
}  

```

Once created, I also checked the mapping:

```auto
{
  "testme": {
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "client": {
          "properties": {
            "geo": {
              "properties": {
                "city_name": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "continent_code": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "country_iso_code": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "country_name": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "location": {
                  "properties": {
                    "lat": {
                      "type": "float"
                    },
                    "lon": {
                      "type": "float"
                    }
                  }
                },
                "postal_code": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "region_iso_code": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "region_name": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "timezone": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                }
              }
            },
            "ip": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "mmdb": {
              "properties": {
                "dma_code": {
                  "type": "long"
                }
              }
            }
          }
        },
        "event": {
          "properties": {
            "original": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        },
        "geoip": {
          "properties": {
            "location": {
              "type": "geo_point"
            }
          }
        },
        "host": {
          "properties": {
            "hostname": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        },
        "message": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "source": {
          "type": "ip"
        }
      }
    }
  }
}

```

I also created a data-view in kibana.

Here is my logstash config:

```auto
input {
    stdin { }
}

filter {

    grok {
        match => { "message" => "%{IP:source}" }
    }

    geoip {
        source => "source"
        target => "client"
    }

}

output {
        elasticsearch {
            hosts => "localhost:9200"
            manage_template => false
            index => "testme"
        }

        stdout {
            codec => rubydebug { }
        }
}

```

Starting logstash and entering an IP gives me this:

```auto
11.11.11.11
{
        "client" => {
          "ip" => "11.11.11.11",
         "geo" => {
                   "city_name" => "Bullard",
                "country_name" => "United States",
            "country_iso_code" => "US",
                 "postal_code" => "75757",
                    "location" => {
                "lon" => -95.3381,
                "lat" => 32.1118
            },
             "region_iso_code" => "US-TX",
              "continent_code" => "NA",
                 "region_name" => "Texas",
                    "timezone" => "America/Chicago"
        },
        "mmdb" => {
            "dma_code" => 709
        }
    },
    "@timestamp" => 2022-09-11T16:23:49.714266Z,
      "@version" => "1",
          "host" => {
        "hostname" => "rocky-8-1"
    },
        "source" => "11.11.11.11",
       "message" => "11.11.11.11",
         "event" => {
        "original" => "11.11.11.11"
    }
}

```

Looks good to me....  
Elasticsearch shows this content:

```auto
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 3,
      "relation": "eq"
    },
    "max_score": 1,
    "hits": [
      {
        "_index": "testme",
        "_id": "oNNdLYMBPd5sI551QSM_",
        "_score": 1,
        "_source": {
          "client": {
            "ip": "11.11.11.11",
            "geo": {
              "city_name": "Bullard",
              "country_name": "United States",
              "country_iso_code": "US",
              "postal_code": "75757",
              "location": {
                "lon": -95.3381,
                "lat": 32.1118
              },
              "region_iso_code": "US-TX",
              "continent_code": "NA",
              "region_name": "Texas",
              "timezone": "America/Chicago"
            },
            "mmdb": {
              "dma_code": 709
            }
          },
          "@timestamp": "2022-09-11T16:23:49.714266Z",
          "@version": "1",
          "host": {
            "hostname": "rocky-8-1"
          },
          "source": "11.11.11.11",
          "message": "11.11.11.11",
          "event": {
            "original": "11.11.11.11"
          }
        }
      },
      {
        "_index": "testme",
        "_id": "ntNaLYMBPd5sI551KiPj",
        "_score": 1,
        "_source": {
          "client": {
            "geo": {
              "timezone": "Europe/Berlin",
              "location": {
                "lon": 9.491,
                "lat": 51.2993
              },
              "continent_code": "EU",
              "country_name": "Germany",
              "country_iso_code": "DE"
            },
            "ip": "5.4.3.2"
          },
          "@timestamp": "2022-09-11T16:20:27.205240Z",
          "@version": "1",
          "host": {
            "hostname": "rocky-8-1"
          },
          "source": "5.4.3.2",
          "message": "5.4.3.2",
          "event": {
            "original": "5.4.3.2"
          }
        }
      },
      {
        "_index": "testme",
        "_id": "n9NaLYMBPd5sI551ayN8",
        "_score": 1,
        "_source": {
          "client": {
            "geo": {
              "timezone": "America/Chicago",
              "location": {
                "lon": -97.822,
                "lat": 37.751
              },
              "continent_code": "NA",
              "country_name": "United States",
              "country_iso_code": "US"
            },
            "ip": "4.3.2.1"
          },
          "@timestamp": "2022-09-11T16:20:43.906904Z",
          "@version": "1",
          "host": {
            "hostname": "rocky-8-1"
          },
          "source": "4.3.2.1",
          "message": "4.3.2.1",
          "event": {
            "original": "4.3.2.1"
          }
        }
      }
    ]
  }
}

```

In Kibana, I see the geo.location field...MAPS shows me the countries based on the 2 field code if I want...but only the geo.location delivers nothing ...(time range is set correctly).

So after 1.5 days of testing and reading...I need help. 1000x Kudos to the chosen one who helps me out.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 11, 2022, 4:59pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/2 "2022-09-11T16:59:16Z")

</div>

Hi @SirStephanikus As Usual You are close .... but just a bit off look carefully at the data and mappings

You mapping and data do not align...

In your data... the actual location field is

`client.geo.location`

```auto
       "_source": {
          "client": {
            "geo": {
              "timezone": "America/Chicago",
              "location": {
                "lon": -97.822,
                "lat": 37.751
              },

```

and your mapping shows this which is NOT a `geo_point` And the mapping shows that is...

```auto
                "location": {
                  "properties": {
                    "lat": {
                      "type": "float"
                    },
                    "lon": {
                      "type": "float"
                    }
                  }
                },

```

That needs to be

The mapping you have at the very top... does not match to any actually data fields because it is not under `client.geo`

```auto
            "location": {
              "type": "geo_point"
            }
          }

```

so it needs to be something like this.... you need to define this ahead of time...  
Plus you should get rid of the `keyword` / `text` multifield and just use `keyword` for most those fields..  
Note I did not do this in an editor so tte `{`s may not match up... but it shows the correct idea

```auto
...
        "client": {
          "properties": {
            "geo": {
              "properties": {
                "city_name": {
                  "type": "keyword"
                  }
                },
                "continent_code": {
                  "type": "keyword"
                  }
                },
                "country_iso_code": {
                  "type": "keyword"
                  }
                },
                "country_name": {
                  "type": "keyword"
                  }
                },
                "location": {
                    "type": "geo_point"
                  }
                },
....

```

---

<div class="post-metadata">

**Author:** ![SirStephanikus](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@SirStephanikus](https://discuss.elastic.co/u/SirStephanikus)\
**Post date:** [September 11, 2022, 7:01pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/3 "2022-09-11T19:01:21Z")

</div>

💡 💡 💡  
I haven't seen the wood because of all the trees (in german, it sound waaayy better).

Oh my god...so simple, just a wrong indexing/mapping of geo...reminds me of a messed up C exam at college.

🥳 I feel like a teen right now (I'm old !), thank you so much Stephen...you took your time to explain something to a stranger on a sunday. I really really appreciate that.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 11, 2022, 7:02pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/4 "2022-09-11T19:02:48Z")

</div>

You are doing just fine!

Did you get the points on the map?

The next things people trip over with the geoip Is they send internal IP addresses which will not turn into a geo and wonder why they don't show up?.

> [@SirStephanikus](#):
>
> I haven't seen the wood because of all the trees (in german, it sound waaayy better).

I totally get it...

---

<div class="post-metadata">

**Author:** ![SirStephanikus](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@SirStephanikus](https://discuss.elastic.co/u/SirStephanikus)\
**Post date:** [September 11, 2022, 7:04pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/5 "2022-09-11T19:04:22Z")

</div>

Yep...everything and my Fail2Ban filebeat -\> Logstash -\> EL \<- Kibana config works too (GROK and custom pattern were easy to me). I labbed this yesterday and the geoip location gave me headache.

FYI:  
Tomorrow I will have a call with one of the ELK people...I'm highly interested in the private training opportunity. Live courses are unfortunately sold out.

> The next things people trip over with the geoip Is they send internal IP addresses which will not turn into a geo and wonder why they don't show up?.

Well...how should you translate PRIVATE addresses ? I mean...there is a reason why it is called PRIVATE. Perhaps one can translate the **global outside ip** of the edge devices IP...which than is an alias everything behind it. I.E.  
internal datacenter VMs are depicted on a map by their external gateway...but never by their internal private address like 172.16.x.x that is just not possible.

What I did for a customer (another monitoring system) was to get the GPS data of all their branches (5k+), displayed it on open-street-map and on this map they got their branch devices linked...but this particular task is not related to ELK, and was more a workaround mapping trick.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [September 12, 2022, 11:52am UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/6 "2022-09-12T11:52:02Z")

</div>

You can have an index with the private addresses geolocated and use the enrich processor to transfer those locations to your ingested events. This is described in this blog post

> **[Enriching Elasticsearch data with GeoIPs from internal, private IP addresses](https://www.elastic.co/blog/enriching-elasticsearch-data-geo-ips-internal-private-ip-addresses)**
>
> Learn a simple way to add geolocation data from private IP addresses to your documents in Elasticsearch using the enrich processor.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 13, 2022, 2:30pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/7 "2022-09-13T14:30:57Z")

</div>

@jsanz Yes thanks I did not realize we had a blog... I wish enrich worked on IP ranges 🙂 not only exact matches... I will bring that up again!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 13, 2022, 3:06pm UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/8 "2022-09-13T15:06:18Z")

</div>

> [@SirStephanikus](#):
>
> Well...how should you translate PRIVATE addresses ?

Since you are using Logstash, this is pretty easy to do with the `translate` filter.

I had a similar use case in the past where I needed to enrich the information from something around 1800 network devices distributed around the country and used a couple of dictionary files and the translate filter.

For example, I had a dictionary file with the name of the devices and the geolocation, something like this:

```auto
"device-0001": [lon, lat]
"device-0002": [lon, lat]
"device-0003": [lon, lat]
"device-NNNN": [lon, lat]

```

Then a translate filter

```auto
translate {
	source => "deviceName"
	target => "[geo][location]"
	dictionary_path => "/path/to/file/locations.yml"
	refresh_interval => 300
}

```

You could use a similar approach to enrich the data of your private addresses, it just depends on how you can filter for each location.

---

<div class="post-metadata">

**Author:** ![SirStephanikus](https://avatars.discourse-cdn.com/v4/letter/s/71e660/32.png) [@SirStephanikus](https://discuss.elastic.co/u/SirStephanikus)\
**Post date:** [September 14, 2022, 11:38am UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/9 "2022-09-14T11:38:16Z")

</div>

So the exact way as described in my post and successfully performed for more than 5k+ branches.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2022, 11:38am UTC](https://discuss.elastic.co/t/no-geoip-points-in-kibana-map/314145/10 "2022-10-12T11:38:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
