# Struggling with geo\_point

**URL:** <https://discuss.elastic.co/t/struggling-with-geo-point/149588>\
**Category:** Kibana\
**Created:** [September 23, 2018, 11:06am UTC](https://discuss.elastic.co/t/struggling-with-geo-point/149588 "2018-09-23T11:06:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcas](https://avatars.discourse-cdn.com/v4/letter/j/b77776/32.png) [@jcas](https://discuss.elastic.co/u/jcas)\
**Post date:** [September 23, 2018, 11:06am UTC](https://discuss.elastic.co/t/struggling-with-geo-point/149588/1 "2018-09-23T11:06:23Z")

</div>

Hey all,

I have a json log file that I want to plot onto maps in Kibana. A sample log entry looks like this:

```
{"ssid": "ABCDEFG", "@timestamp": "2018-09-22T17:20:35.000Z", "longitude": "12.345678901", "geo_point": "98.12345678,12.345678901", "device_type": "Client", "mac_address": "XX:XX:XX:XX:XX:XX", "latitude": "98.12345678", "rssi": "-55", "channel": "3", "manufacturer": "unknown"}

```

Kibana shows geo\_point, latitude, and longitude as string types. I obviously need them to be geo\_point in order to map them. This is my first time dealing with geo\_point in kibana and I'm struggling to make sense of the various documentation articles on the matter.

What's the safest way to go about this? I can manipulate every point of this to include how the json log is written. Would it be best that I manipulate the json log format to be something like _{"geopoint":{"latitude":"98.12345678", "longitude":"12.345678901"}}_ or would I be better off mutating this data in logstash or via elasticsearch?

If manipulating how the json data is written is not the correct way to go about this, step-by-step what do I need to do to configure the elastic stack to process this data correctly?

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [September 25, 2018, 5:43am UTC](https://discuss.elastic.co/t/struggling-with-geo-point/149588/2 "2018-09-25T05:43:41Z")

</div>

You will need to make sure that the geo\_point field is a geo\_point type.

Here is the example I created:

```auto
PUT discuss-149588
{
    "settings" : {
        "number_of_shards" : 1
    },
    "mappings" : {
        "doc" : {
            "properties" : {
                "geo_point" : { "type" : "geo_point" },
                "device_type": { "type": "keyword" },
                "mac_address": { "type": "text" },
                "ssid": { "type": "keyword" }
            }
        }
    }
}

POST discuss-149588/doc
{
  "geo_point": "45.516020,-122.681430",
  "device_type": "Client",
  "mac_address": "XX:XX:XX:XX:XX:XX",
  "ssid": "ABCDEFG"
}

```

With this I can add the index pattern `discuss-149588`. On the index pattern page, you can verify that the geo\_point the correct type:

![55](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d44a3132b174cdd23b088e10b734757d2c5bb8e.png)

Now, you can create a Coordinate Map using your new index.

![31](https://us1.discourse-cdn.com/elastic/original/3X/3/9/394e9223babd9f983c1b7aa5484c7e2faf2e4736.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2018, 5:46am UTC](https://discuss.elastic.co/t/struggling-with-geo-point/149588/3 "2018-10-23T05:46:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
