# Problems with displaying the map in the dashboard

**URL:** <https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771>\
**Category:** Kibana\
**Created:** [October 16, 2025, 9:33am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771 "2025-10-16T09:33:43Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alberto\_Russo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_russo/32/140410_2.png) [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Post date:** [October 16, 2025, 9:33am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/1 "2025-10-16T09:33:43Z")

</div>

I installed the official Elastic integration to collect 365 logs. Using the dashboard that provides the integration, I see nothing in the map section (see image). Has anyone encountered this issue? Or does anyone know how to fix it?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1d124dc31b7cd4f654877d8235e17071376524ff.jpeg)

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 20, 2025, 7:27am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/2 "2025-10-20T07:27:20Z")

</div>

Hello @Alberto_Russo

Could you please check the data in logs-\* if it is valid & has a geo field along with the time duration selected for the dashboard ?

Similar issue in below post :

> [@Unable to view any data in Kibana maps](https://discuss.elastic.co/t/unable-to-view-any-data-in-kibana-maps/382642/2):
>
> Hello @ramenon Welcome to the community!! The reason could be that in the time duration selected of 4 months could you please check if there is data available in the dataview because of which we do not see any information on the maps or the field which is selected has geopoint field? Tried for kibana sample data flight and do not see any issue : Thanks!!

Thanks!!

---

<div class="post-metadata">

**Author:** ![Alberto\_Russo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_russo/32/140410_2.png) [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Post date:** [October 23, 2025, 7:35am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/3 "2025-10-23T07:35:37Z")

</div>

Hi @Tortoise,

in logs of 365 i have these data, but i think isn’t geopoint.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff1dc15e57f0cf8226e991b9952b7434dba1252c.png)

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 23, 2025, 9:56am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/4 "2025-10-23T09:56:39Z")

</div>

Thanks @Alberto_Russo for sharing the document, looking at the details it look a valid geo location.

Still could you please check the field mapping :

GET your\_index/\_mapping

If the location is :

"location": {  
"type": "geo\_point"  
}

Also check the logs-\* dataview which you are selecting has the updated 365 logs as part of the dataview

Thanks!!

---

<div class="post-metadata">

**Author:** ![Alberto\_Russo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_russo/32/140410_2.png) [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Post date:** [October 23, 2025, 10:08am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/5 "2025-10-23T10:08:02Z")

</div>

Aftet GET request ’GET logs-o365.audit\*/\_mapping’ this is my output in relation of location

```auto
"source": {
"properties": {
"as": {
  "properties": {
	"number": {
	  "type": "long"
	},
	"organization": {
	  "properties": {
		"name": {
		  "type": "keyword",
		  "ignore_above": 1024
		}
	  }
	}
  }
},
"geo": {
  "properties": {
	"city_name": {
	  "type": "keyword",
	  "ignore_above": 1024
	},
	"continent_name": {
	  "type": "keyword",
	  "ignore_above": 1024
	},
	"country_iso_code": {
	  "type": "keyword",
	  "ignore_above": 1024
	},
	"country_name": {
	  "type": "keyword",
	  "ignore_above": 1024
	},
	"location": {
	  "properties": {
		"lat": {
		  "type": "float"
		},
		"lon": {
		  "type": "float"
		}
	  }
	},
	"region_iso_code": {
	  "type": "keyword",
	  "ignore_above": 1024
	},
	"region_name": {
	  "type": "keyword",
	  "ignore_above": 1024
	}
  }

```

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 23, 2025, 10:35am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/6 "2025-10-23T10:35:55Z")

</div>

Hello @Alberto_Russo

Thanks for sharing the output and as it is a object mapping & not geopoint that might be the reason for a blank map :

```auto
"location": {
	  "properties": {
		"lat": {
		  "type": "float"
		},
		"lon": {
		  "type": "float"
		}
	  }
	}

```

As we select the dataview while creating a map it list the valid fields which can be selected for you this might be empty :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9bd86d028047199d9e7ce9d953e9d4f035fe0bce.jpeg)

Thanks!!

---

<div class="post-metadata">

**Author:** ![Alberto\_Russo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_russo/32/140410_2.png) [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Post date:** [October 23, 2025, 10:39am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/7 "2025-10-23T10:39:53Z")

</div>

So I need to change the type? From Object to Geopoint? How I can do it?

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [October 23, 2025, 12:04pm UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/8 "2025-10-23T12:04:02Z")

</div>

are these mappings from the official o365 integration?

What version are you on (elasticsearch and the integration please)

---

<div class="post-metadata">

**Author:** ![Alberto\_Russo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_russo/32/140410_2.png) [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Post date:** [October 23, 2025, 12:14pm UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/9 "2025-10-23T12:14:10Z")

</div>

Hello @RainTown,

This is my current version of Integration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/c/9c03ddca28e575fa70b9fd6912e238db2aeb546f.png)

and this is my ELK version:

```auto
{
  "name": "securityonion",
  "cluster_name": "securityonion",
  "cluster_uuid": "WrQ4IVzfSvWajD63YjDhAg",
  "version": {
    "number": "8.18.6",
    "build_flavor": "default",
    "build_type": "docker",
    "build_hash": "970b6c3ae853753ae66a12c1208c85a3c9728d92",
    "build_date": "2025-08-25T22:05:47.180118464Z",
    "build_snapshot": false,
    "lucene_version": "9.12.1",
    "minimum_wire_compatibility_version": "7.17.0",
    "minimum_index_compatibility_version": "7.0.0"
  },
  "tagline": "You Know, for Search"
}

```

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [October 23, 2025, 12:32pm UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/10 "2025-10-23T12:32:14Z")

</div>

Thanks. I note and 2.31.0 is the latest version, supposed to be compatible with your ES version, so you might wish to upgrade (under Settings)

But what I don’t understand is that the fields you shared, which were a subset of the mapping, don’t match the [documentation](https://www.elastic.co/docs/reference/integrations/o365) or the example doc. Can you share the complete mapping?

Was this ever working, i.e. with previous versions of either ES or the integration, or is this something you are using for first time?

---

<div class="post-metadata">

**Author:** ![Alberto\_Russo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alberto_russo/32/140410_2.png) [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Post date:** [October 23, 2025, 12:35pm UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/11 "2025-10-23T12:35:56Z")

</div>

This is my first time using it, as with ELK Stack. I'll send you the full output of the command?

```auto
GET logs-o365.audit*/_mapping

```

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 24, 2025, 3:06am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771/12 "2025-10-24T03:06:38Z")

</div>

Hello @Alberto_Russo

As per the screenshot shared the integration will have default Assets which you can check and see if it is useful because as per the screenshot i see a map as well :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0da8439bf86b164c0a18f41d6b991d6c89f4c31b.jpeg)

Thanks!!
