# Private ips and dns name into the worldmap

**URL:** <https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325>\
**Category:** Logstash\
**Created:** [September 30, 2017, 6:26am UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325 "2017-09-30T06:26:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikolay\_Petrov](https://avatars.discourse-cdn.com/v4/letter/n/4af34b/32.png) [@Nikolay\_Petrov](https://discuss.elastic.co/u/Nikolay_Petrov)\
**Post date:** [September 30, 2017, 6:26am UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/1 "2017-09-30T06:26:54Z")

</div>

Hi folks!  
Just think about any chance how to perform visualization over the wordlmap in case I've manipulate with domain name or internal ip?  
Any mechanism to do that?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 30, 2017, 7:19am UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/2 "2017-09-30T07:19:35Z")

</div>

[Creating geoip data for internal networks](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729/) is the best way I have seen to do this 🙂

---

<div class="post-metadata">

**Author:** ![Nikolay\_Petrov](https://avatars.discourse-cdn.com/v4/letter/n/4af34b/32.png) [@Nikolay\_Petrov](https://discuss.elastic.co/u/Nikolay_Petrov)\
**Post date:** [September 30, 2017, 10:37pm UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/3 "2017-09-30T22:37:23Z")

</div>

Awesome, thanks!  
, but still get an issue with mapping type:

> ```
> {
> "proc-events-2017.09.30": {
> "aliases": {},
> "mappings": {
> "proc-events": {
> "properties": {
> "@timestamp": {
> "type": "date"
> },
> "geoip": {
> "properties": {
> "location": {
> "type": "float"
> },
> ...
> }
> 
> ```

How to change correctly, 'location' mapping to be a 'geo\_point' type by default, or at least change it after?

in conf.d/proc:

> ...  
> geoip {  
> source =\> "src\_ip"  
> target =\> "geoip"  
> }  
> if [src\_ip] =~ /^10.51.4/ or [src\_ip] =~ /^10.51.5/ or [src\_ip] =~ /^10.51.6/ {  
> mutate { replace =\> { "[geoip][timezone]" =\> "Pacific" } }  
> mutate { replace =\> { "[geoip][reg]" =\> "us" } }  
> mutate { remove\_field =\> ["[geoip][location]" ] }  
> mutate { add\_field =\> { "[geoip][location]" =\> "-121.867905" } }  
> mutate { add\_field =\> { "[geoip][location]" =\> "37.279518" } }  
> mutate { convert =\> ["[geoip][location]", "float" ] }  
> mutate { replace =\> { "[geoip][latitude]" =\> 37.279518 } }  
> mutate { convert =\> ["[geoip][latitude]", "float" ] }  
> mutate { replace =\> { "[geoip][longitude]" =\> -121.867905 } }  
> mutate { convert =\> ["[geoip][longitude]", "float" ] }  
> }  
> ...

, but in case of put it as:

> mutate { convert =\> ["[geoip][location]", "geo\_point" ] }

got an error

in my output:

> ...  
> manage\_template =\> false  
> ...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2017, 12:49am UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/4 "2017-10-01T00:49:37Z")

</div>

What's the mapping on the field show?

---

<div class="post-metadata">

**Author:** ![Nikolay\_Petrov](https://avatars.discourse-cdn.com/v4/letter/n/4af34b/32.png) [@Nikolay\_Petrov](https://discuss.elastic.co/u/Nikolay_Petrov)\
**Post date:** [October 1, 2017, 6:42am UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/5 "2017-10-01T06:42:40Z")

</div>

```
      "geoip": {
        "properties": {
          "location": {
            "type": "float"
          },

```

![Screenshot from 2017-10-01 09-52-18](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d33a51b95528b0f42f11db18448b2bcb3f0c064c.png)

---

<div class="post-metadata">

**Author:** ![Nikolay\_Petrov](https://avatars.discourse-cdn.com/v4/letter/n/4af34b/32.png) [@Nikolay\_Petrov](https://discuss.elastic.co/u/Nikolay_Petrov)\
**Post date:** [October 2, 2017, 2:34pm UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/6 "2017-10-02T14:34:08Z")

</div>

The case is fixed with separate template creation and assignment to upcoming indexes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2017, 2:34pm UTC](https://discuss.elastic.co/t/private-ips-and-dns-name-into-the-worldmap/102325/7 "2017-10-30T14:34:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
