# Private ip geoip JSON object / structure and some questions

**URL:** <https://discuss.elastic.co/t/private-ip-geoip-json-object-structure-and-some-questions/156555>\
**Category:** Logstash\
**Created:** [November 13, 2018, 10:21pm UTC](https://discuss.elastic.co/t/private-ip-geoip-json-object-structure-and-some-questions/156555 "2018-11-13T22:21:21Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![ppafford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppafford/32/36533_2.png) [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Post date:** [November 14, 2018, 2:47am UTC](https://discuss.elastic.co/t/private-ip-geoip-json-object-structure-and-some-questions/156555/3 "2018-11-14T02:47:01Z")

</div>

Side Note: Im using Fliebeat Apache Module and updating the index from filebeat-\* to logstash-\* (This is working) just wanted to add this info just in case this changes how to proceed

from [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

```
GET /_all/_mapping

```

output

```
"geoip": {
"properties": {
	"city_name": {
		"type": "keyword",
		"ignore_above": 1024
	},
	"continent_name": {
		"type": "keyword",
		"ignore_above": 1024
	},
	"country_iso_code": {
		"type": "keyword",
		"ignore_above": 1024
	},
	"location": {
		"type": "geo_point"
	},
	"region_iso_code": {
		"type": "keyword",
		"ignore_above": 1024
	},
	"region_name": {
		"type": "keyword",
		"ignore_above": 1024
	}
}

```

also follow up on the location, does lat or lon need to go first? I saw this post [Creating geoip data for internal networks](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/2?u=ppafford) but wanted to confirm

Im not sure what else Im missing to see them be in the map view

---

_[View the full topic](https://discuss.elastic.co/t/private-ip-geoip-json-object-structure-and-some-questions/156555)._
