# Problems with geo\_point

**URL:** <https://discuss.elastic.co/t/problems-with-geo-point/140967>\
**Category:** Logstash\
**Created:** [July 20, 2018, 9:31pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967 "2018-07-20T21:31:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![noob\_cakes](https://avatars.discourse-cdn.com/v4/letter/n/edb3f5/32.png) [@noob\_cakes](https://discuss.elastic.co/u/noob_cakes)\
**Post date:** [July 20, 2018, 9:31pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/1 "2018-07-20T21:31:51Z")

</div>

Hello all,

I'm very new to elastic, so please bear with me. I'm trying to get a data type 'geo\_point' in ES 6.3 via a template referenced in my logstash pipeline. I'm getting geo data populating in elasticsearch, just not a geo\_point data type that's usable with the coordinate map. Here's my ES template:

> {  
> "template" : "paloalto-_",  
> "version" : 60001,  
> "settings" : {  
> "index.refresh\_interval" : "5s"  
> },  
> "mappings" : {  
> "default" : {  
> "dynamic\_templates" : [ {  
> "message\_field" : {  
> "path\_match" : "message",  
> "match\_mapping\_type" : "string",  
> "mapping" : {  
> "type" : "text",  
> "norms" : false  
> }  
> }  
> }, {  
> "string\_fields" : {  
> "match" : "_",  
> "match\_mapping\_type" : "string",  
> "mapping" : {  
> "type" : "text", "norms" : false,  
> "fields" : {  
> "keyword" : { "type": "keyword", "ignore\_above": 256 }  
> }  
> }  
> }  
> } ],  
> "properties" : {  
> "@timestamp": { "type": "date"},  
> "@version": { "type": "keyword"},  
> "DestinationGeo" : {  
> "dynamic": true,  
> "properties" : {  
> "ip": { "type": "ip" },  
> "location" : { "type" : "geo\_point" },  
> "latitude" : { "type" : "half\_float" },  
> "longitude" : { "type" : "half\_float" }  
> }  
> }  
> }  
> }  
> }  
> }

And here's the relevant section from my pipeline:

> if [DestinationAddress] and [DestinationAddress] !~ "(^127.0.0.1)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^192.168.)|(^169.254.)" {  
> geoip {  
> database =\> "/opt/logstash/GeoLite2-City.mmdb"  
> source =\> "DestinationAddress"  
> target =\> "DestinationGeo"  
> }  
> #Delete 0,0 in DestinationGeo.location if equal to 0,0  
> if ([DestinationGeo.location] and [DestinationGeo.location] =~ "0,0") {  
> mutate {  
> replace =\> ["DestinationAddress.location", ""]  
> }  
> }  
> }  
> output {  
> if [Type] == "TRAFFIC" {  
> elasticsearch {  
> index =\> "paloalto-traffic-%{DeviceName}-%{+YYYY.MM.dd}"  
> template =\> "/opt/logstash/elasticsearch-template.json"  
> template\_overwrite =\> true  
> }  
> }  
> }

I'm not seeing any errors, so I assume I've misunderstood a piece of this. Can anyone see anything obvious missing from this configuration that would prevent the geo\_point data field from populating? Do I need to install the geoip plugin on all nodes before this field will show up?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 20, 2018, 9:48pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/2 "2018-07-20T21:48:19Z")

</div>

there are a couple of "gotcha"s here.

- The template is just a _template_, used by Elasticsearch when creating new indices. Updating it does not update indices that already exist.
- Due to the way Elasticsearch uses Lucene under the hood, it is not possible to _change_ the type of a field in an index so you may have to delete the index and start over (or index to a new field with a new name and use it instead)

---

<div class="post-metadata">

**Author:** ![noob\_cakes](https://avatars.discourse-cdn.com/v4/letter/n/edb3f5/32.png) [@noob\_cakes](https://discuss.elastic.co/u/noob_cakes)\
**Post date:** [July 20, 2018, 9:53pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/3 "2018-07-20T21:53:25Z")

</div>

Hi yaauie, thanks for the reply. I've deleted the index after any changes to the template and let the index recreate applying the new template. I'm still not getting any geo\_point data types in my datasets within ES. I feel like I've got something mapped wrong, but my understanding of templates is pretty limited at the moment.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 20, 2018, 10:05pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/4 "2018-07-20T22:05:30Z")

</div>

Nothing specific is standing out to me about your template.

What is the current index mapping? The [_Get Mapping API_](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/indices-get-mapping.html) is useful here.

---

<div class="post-metadata">

**Author:** ![noob\_cakes](https://avatars.discourse-cdn.com/v4/letter/n/edb3f5/32.png) [@noob\_cakes](https://discuss.elastic.co/u/noob_cakes)\
**Post date:** [July 20, 2018, 10:17pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/5 "2018-07-20T22:17:07Z")

</div>

It's a lot of data, too much to post. It looks like there are two fields for "DestinationGeo". I'm guessing that is my issue?

> ```
> "DestinationGeo" : {
> "dynamic" : "true",
> "properties" : {
> "ip" : {
> "type" : "ip"
> },
> "latitude" : {
> "type" : "half_float"
> },
> "location" : {
> "type" : "geo_point"
> },
> "longitude" : {
> "type" : "half_float"
> }
> 
> ```

> ```
> "DestinationGeo" : {
> "dynamic" : "true",
> "properties" : {
> "city_name" : {
> "type" : "text",
> "norms" : false,
> "fields" : {
> "keyword" : {
> "type" : "keyword",
> "ignore_above" : 256
> }
> }
> },
> "continent_code" : {
> "type" : "text",
> "norms" : false,
> "fields" : {
> "keyword" : {
> "type" : "keyword",
> "ignore_above" : 256
> }
> }
> },
> "country_code2" : {
> "type" : "text",
> "norms" : false,
> "fields" : {
> "keyword" : {
> "type" : "keyword",
> "ignore_above" : 256
> }
> }
> },
> "country_code3" : {
> "type" : "text",
> "norms" : false,
> "fields" : {
> "keyword" : {
> "type" : "keyword",
> "ignore_above" : 256
> }
> }
> },
> "country_name" : {
> "type" : "text",
> "norms" : false,
> "fields" : {
> "keyword" : {
> "type" : "keyword",
> "ignore_above" : 256
> }
> }
> },
> 
> ```

Also here's the JSON that's getting passed into ES:

> ```
> "DestinationGeo": {
> "country_code2": "US",
> "region_code": "CA",
> "longitude": -122.0574,
> "latitude": 37.419200000000004,
> "city_name": "Mountain View",
> "region_name": "California",
> "country_code3": "US",
> "location": {
> "lon": -122.0574,
> "lat": 37.419200000000004
> },
> 
> ```

But the data type is '?' for almost all of my geo data where other data types are defined. So I guess I'm missing a definer somewhere for the datatype and ES is just making a best effort?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 20, 2018, 10:33pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/6 "2018-07-20T22:33:15Z")

</div>

Elasticsearch can't have two fields with the same name in an index, so something's not quite right; can you paste the entire mapping in a [gist](https://gist.github.com/) and link to it?

---

<div class="post-metadata">

**Author:** ![noob\_cakes](https://avatars.discourse-cdn.com/v4/letter/n/edb3f5/32.png) [@noob\_cakes](https://discuss.elastic.co/u/noob_cakes)\
**Post date:** [July 20, 2018, 10:38pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/7 "2018-07-20T22:38:48Z")

</div>

Sure, [Here's the link](https://gist.github.com/tnesmithWasTaken/7955d9ab03edc90066d4beeaa8922630). Is it because I am using the same field name in the Template that I am using in the logstash pipeline? If so, should I just change the template field to another name? I thought the template was supposed to reference the field being processed.. am I completely wrong on that?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 20, 2018, 11:57pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/8 "2018-07-20T23:57:52Z")

</div>

The top-level wildcards indicate to me that the doc you linked to was probably your _templates_. Can you get the _effective_ mapping from the specific index?

```auto
curl -X GET "${hostname}:${port}/${index}/_mapping/_doc"

```

We're stretching pretty firmly into Elasticsearch territory, so it may be helpful to post your questions in the Elasticsearch forum.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2018, 11:57pm UTC](https://discuss.elastic.co/t/problems-with-geo-point/140967/9 "2018-08-17T23:57:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
