# Template mapping dosen't work

**URL:** <https://discuss.elastic.co/t/template-mapping-dosent-work/131130>\
**Category:** Logstash\
**Created:** [May 9, 2018, 8:45am UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130 "2018-05-09T08:45:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [May 9, 2018, 8:45am UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/1 "2018-05-09T08:45:16Z")

</div>

I'm trying to convert latitude and longitude to geo\_point location in order to use it a map visulaztion.

this is my configuration:

```
input{

   file{
	path=>"C:\Users\Ahmed\Desktop\311_Service_Requests_from_2015.csv"
            start_position=>"beginning"
             sincedb_path=>NUL
       }
     }
filter{
    
      csv{
          separator=>","
          columns=>["Unique Key","Created Date","Closed Date","Agency","Agency Name","Complaint Type","Descriptor","Location Type","Incident Zip","Incident Address","Street Name","Cross Street 1","Cross Street 2","Intersection Street 1","Intersection Street 2","Address Type","City","Landmark","Facility Type","Status","Due Date","	Resolution Description","Resolution Action Updated Date","Community Board","Borough","X Coordinate (State Plane)","Y Coordinate (State Plane)","Park Facility Name","Park Borough","School Name","School Number","School Region","School Code","School Phone Number",	"School Address","School City","School State","School Zip","School Not Found","School or Citywide Complaint","Vehicle Type","Taxi Company Borough","Taxi Pick Up Location","Bridge Highway Name","Bridge Highway Direction","Road Ramp","Bridge Highway Segment","Garage Lot Name","Ferry Direction","Ferry Terminal Name","Latitude","Longitude","Location"]

         }
     mutate{
         convert=>["Latitude","float"]
	 convert=>["Longitude","float"]	
	 rename=>["Latitude","[location][lat]"]	
 	 rename=>["Longitude","[location][lon]"]
 	 }	            

     date{ 
    	match=>["Created Date","MM/dd/yyyy HH:mm:ss aa"]
    	target=>"Date"	
    	}
}

output{	
     
 elasticsearch {
         hosts=> "localhost"
         index=> "nyc311calls7"
        document_type=>"calls"
       }        
 stdout{codec=>rubydebug}
  }

```

i see in a [youtube](https://www.youtube.com/watch?v=mPHvJBJcC5M&list=LLMx0bPm1vFEgjNZOB94aB5Q) that i need t o add this template before creating the index pattern:

```
put _template/nyc*311*7
{
 "order":0,
  "index_patterns":"nyc*311*7",
  "mapping":{
   "_default":{
  "properties":{
    "location ":{
      "type":"geo_point"
       }
     }
   }
 }
}

```

but that dosen't convert the location to a geo\_point, what i am doing wrong ?

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [May 9, 2018, 1:16pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/2 "2018-05-09T13:16:34Z")

</div>

@thomasneirynck ?

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [May 9, 2018, 1:33pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/3 "2018-05-09T13:33:38Z")

</div>

hi @akml_kk

What data type is your location field? Can you paste the mapping of your index here? Can you also paste a few example documents so we can see how are they getting indexed instead.

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [May 9, 2018, 1:59pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/4 "2018-05-09T13:59:33Z")

</div>

hello,  
i didn't get a location field in kibana,instead i get this two fields:  
location.lat and location.lon and they are both floats. ![kibana](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4ac3bc8b3506419d4f96e931e69751207b5490b6.png)

this is what i get for the mapping :  
"mappings": {  
"calls": {  
"properties": {  
"\tResolution Description": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Address Type": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Agency": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Agency Name": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Borough": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},

i can't paste it all, your site limit me to paste 7000 character

since i don't know how to get example documents what do you mean or how ?

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [May 9, 2018, 2:02pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/5 "2018-05-09T14:02:46Z")

</div>

i can tell you also that there is no geoip field in mapping and this is how it looks the location field :

```
  "location": {
        "properties": {
          "lat": {
            "type": "float"
          },
          "lon": {
            "type": "float"
          }
        }
```

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [May 9, 2018, 2:18pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/6 "2018-05-09T14:18:34Z")

</div>

this is the mapping of another index (just a simple example to show you how the mapping works in my machine) :

{  
"hello\_world": {  
"mappings": {  
"hello\_world": {  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"host": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"message": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"path": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [May 9, 2018, 2:20pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/7 "2018-05-09T14:20:24Z")

</div>

it seems like your field is not a geo\_point, just a nested field with two floats.

It seems like your logstash script isn't picking up the template. I'm not a huge logstash expert, so I would ask this question in the forum there: [https://discuss.elastic.co/c/logstash](https://discuss.elastic.co/c/logstash). Maybe you started indexing the data before creating the template?

With example document, I just meant an example of one of the docs, e.g. the individual incidents you see in the Discovery-app of Kibana. But at this point, it looks like mapping of the index is wrong.

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [May 9, 2018, 2:25pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/8 "2018-05-09T14:25:12Z")

</div>

no , i created the template before ingesting the data , this is what logstash return before beginning the pipline :

 ![elk](https://us1.discourse-cdn.com/elastic/original/3X/8/5/85ca8e4e8d4f174db245068fafe938cb0ad9b514.png)

ok,i will ask it then in logstash

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2018, 5:51pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/9 "2018-05-09T17:51:14Z")

</div>

The template that Logstash installs for you applies to indexes whose name matches logstash-\* but you're sending the documents to the nyc311calls7 index.

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [May 9, 2018, 6:08pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/10 "2018-05-09T18:08:53Z")

</div>

but i have defined the template like this :

```
put _template/nyc*311*7
 {
 "order":0,
 "index_patterns":"nyc*311*7",
  "mapping":{
  "_default":{
  "properties":{
     "location ":{
      "type":"geo_point"
       }
 }
  }
}
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2018, 8:01pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/11 "2018-05-09T20:01:02Z")

</div>

Okay, it wasn't clear that you created your template outside of Logstash.

> ```
> "location ":{
> 
> ```

Do you really have a space after "location"?

To debug things like this, create an index yourself after applying the template and fetch the mappings afterwards. Are they what you expect?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2018, 8:57pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/12 "2018-05-09T20:57:32Z")

</div>

Copying the solution from the [other thread](https://discuss.elastic.co/t/location-dosent-convert-to-geo-point/131199) to this one... "mapping" should be "mappings", "location " needs that space to be removed. "\_default" should be "\_default\_" (or "calls", since that is the document type).

This works.

```auto
PUT _template/nyc 
 {
    "order":0,
    "index_patterns":"nyc",
    "mappings":{
      "_default_":{
        "properties":{
          "location":{
            "type":"geo_point"
          }
        }
      }
    }
 }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2018, 8:57pm UTC](https://discuss.elastic.co/t/template-mapping-dosent-work/131130/13 "2018-06-06T20:57:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
