# \[Solved\] Logstash geoip vs. ES 2.x "no dot in fields"

**URL:** <https://discuss.elastic.co/t/solved-logstash-geoip-vs-es-2-x-no-dot-in-fields/50735>\
**Category:** Logstash\
**Created:** [May 23, 2016, 3:05pm UTC](https://discuss.elastic.co/t/solved-logstash-geoip-vs-es-2-x-no-dot-in-fields/50735 "2016-05-23T15:05:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ppuschmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppuschmann/32/146751_2.png) [@ppuschmann](https://discuss.elastic.co/u/ppuschmann)\
**Post date:** [May 23, 2016, 3:05pm UTC](https://discuss.elastic.co/t/solved-logstash-geoip-vs-es-2-x-no-dot-in-fields/50735/1 "2016-05-23T15:05:19Z")

</div>

Hi there,

we're currently using the following Logstash-Filter for geoip-processing:

```
geoip {
  source => "client_ip"
  lru_cache_size => 10000
}

```

This creates for example the following output:

```
"geoip" => {
  "ip" => "8.8.4.4",
  "country_code2" => "US",
  "country_code3" => "USA",
  "country_name" => "United States",
  "continent_code" => "NA",
  "region_name" => "CA",
  "city_name" => "Mountain View",
  "postal_code" => "94043",
  "latitude" => 37.41919999999999,
  "longitude" => -122.0574,
  "dma_code" => 807,
  "area_code" => 650,
  "timezone" => "America/Los_Angeles",
  "real_region_name" => "California",
  "location" => [
    [0] -122.0574,
    [1] 37.41919999999999
  ]
}

```

We're still using Logstash 1.5.x with ES 1.7.x but plan to upgrade to ES 2.x.  
But here we experience the problem of "dots in fieldnames not supported".

-\> [https://www.elastic.co/guide/en/logstash/current/\_upgrading\_logstash\_and\_elasticsearch\_to\_2\_0.html](https://www.elastic.co/guide/en/logstash/current/_upgrading_logstash_and_elasticsearch_to_2_0.html)

-\> [https://www.elastic.co/guide/en/elasticsearch/reference/2.0/breaking\_20\_mapping\_changes.html#\_field\_names\_may\_not\_contain\_dots](https://www.elastic.co/guide/en/elasticsearch/reference/2.0/breaking_20_mapping_changes.html#_field_names_may_not_contain_dots)

How can we modify the geoip-filter to match the requirements of ES 2.x?

The useragent-filter has "prefix", but "geoip" hasn't.

What are possible solutions?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 23, 2016, 3:44pm UTC](https://discuss.elastic.co/t/solved-logstash-geoip-vs-es-2-x-no-dot-in-fields/50735/2 "2016-05-23T15:44:45Z")

</div>

I'm not sure I see the problem. Where are the dots in the fields from the GeoIP filter? Yes, the fields are structured, but there are no actual dots in the fields. Elasticsearch and Kibana may even refer to the nested structure with dots, but again, here there are no dots.

---

<div class="post-metadata">

**Author:** ![ppuschmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppuschmann/32/146751_2.png) [@ppuschmann](https://discuss.elastic.co/u/ppuschmann)\
**Post date:** [May 24, 2016, 7:11am UTC](https://discuss.elastic.co/t/solved-logstash-geoip-vs-es-2-x-no-dot-in-fields/50735/3 "2016-05-24T07:11:29Z")

</div>

Hi,

you're totally right. There is no real problem regarding Logstash.

Our migration plugin complains about geoip:

```
Dots in field names lead to ambiguous field resolution, in fields:
  _default_:geoip\.location, curator:geoip\.location, ...

```

But now it really looks like a problem with our index-templates:

```
{
  "template_1": {
    "order": 0,
    "template": "indexname-*",
    "settings": {},
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "message_field": {
              "mapping": {
                "index": "analyzed",
                "omit_norms": true,
                "type": "string",
                "fields": {
                  "raw": {
                    "ignore_above": 256,
                    "index": "not_analyzed",
                    "type": "string"
                  }
                }
              },
              "match_mapping_type": "string",
              "match": "message"
            }
          }
        ],
        "properties": {
          "geoip.location": {
            "type": "geo_point",
            "lat_lon": true
          }
        }
      }
    },
    "aliases": {}
  }
}

```

The mapping of `geoip.location` is wrong and therefore creating problems with the migration-plugin.

Sorry for bothering you and thank you for pointing me into the right direction!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:56am UTC](https://discuss.elastic.co/t/solved-logstash-geoip-vs-es-2-x-no-dot-in-fields/50735/4 "2017-07-06T04:56:31Z")

</div>


