# Til Map - failed to show locations in map, error: the database provided is invalid or corrupted

**URL:** https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122
**Category:** Logstash
**Created:** [September 1, 2017, 12:03pm UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122 "2017-09-01T12:03:15Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![ashleyl](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@ashleyl](https://discuss.elastic.co/u/ashleyl)
#### Post date: [September 1, 2017, 12:03pm UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/1 "2017-09-01T12:03:15Z")

</div>

Hi Elastic Support Manager,

Please help to check how to fix below issues.  
I use filebeat send log to logstash-elasticsearch-kibana(host).  
Kibana - Version: 5.4.2  
logstash 5.5.1  
filebeat version 5.5.1

Issues:  
(1)Til Map - failed to show locations in map  
(2)After set (database =\> "/etc/logstash/GeoLiteCity.dat") in below logstash config file(10-django-filter.conf),failed to flush data to elasticsearch  
logstash worked well without database =\> "/etc/logstash/GeoLiteCity.dat"  
GeoLiteCity.dat was downloaded from [http://dev.maxmind.com/geoip/geoip2/geolite2/](http://dev.maxmind.com/geoip/geoip2/geolite2/)

=============================================================================  
[Logstash filter]  
filter {  
if [type] == "log" {  
grok {  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name  
}]) ([%{LOGLEVEL:log\_level}])-%{GREEDYDATA:uri\_path}"}  
overwrite =\> ["message"]  
}  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
merge =\> {"[tags]" =\> "[fields][tags]"}  
remove\_field =\> "[fields][tags]"  
}  
date {  
match =\> ["logDate", "yyyy-MM-dd HH:mm:ss,SSS"]  
timezone =\> "Asia/Taipei"  
target =\> "@timestamp"  
}  
}

=============================================================================  
[filebeat.yml]  
filebeat.prospectors:

- input\_type: log  
paths:

Thanks,  
Ashley

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [September 2, 2017, 9:05pm UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/2 "2017-09-02T21:05:55Z")

</div>

What happens if you use the default, included database?

---

<div class="post-metadata">

### Author: ![ashleyl](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@ashleyl](https://discuss.elastic.co/u/ashleyl)
#### Post date: [September 4, 2017, 11:23am UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/3 "2017-09-04T11:23:53Z")

</div>

Thank you for the quick reply.

Sorry could you please help to clarify the default setting with database means below, exclude mutate plugin?

geoip {  
source =\> "clientip"  
target =\> “geoip"  
database =\> “/etc/logstash/GeoLiteCity.dat"  
}

Thanks,  
Ashley

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [September 6, 2017, 3:29am UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/4 "2017-09-06T03:29:54Z")

</div>

> [@ashleyl](#):
>
> database =\> “/etc/logstash/GeoLiteCity.dat”

Just remove that line and see what happens.

---

<div class="post-metadata">

### Author: ![ashleyl](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@ashleyl](https://discuss.elastic.co/u/ashleyl)
#### Post date: [September 8, 2017, 12:39pm UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/5 "2017-09-08T12:39:37Z")

</div>

I removed database, but still failed.

I found my symptom is the same as this:

> [@Index pattern does not contain any of the following field types: geo\_point](https://discuss.elastic.co/t/index-pattern-does-not-contain-any-of-the-following-field-types-geo-point/85001):
>
> I've got geoip fields with filter geoip in logstash. [image] But I can't visualize in kibana [image] How can I fix this? Any help will be appreciated.

But I still don't know how to change my location filed to geo-ip type.

I tried to apply template, but nothing happens.  
(Referred Source: [[elasticesearch] index pattern does not contain any of the following field types: geo\_point | by be:theproud | Medium](https://medium.com/@logan.81k/elasticesearch-index-pattern-does-not-contain-any-of-the-following-field-types-geo-point-34af9463502f))  
curl -XPUT '[http://localhost:9200/\_template/django](http://localhost:9200/_template/django)' -d@/etc/filebeat/filebeat.template.json  
{"acknowledged":true}

Could you please provide more clear information about how to change it?  
It seems many people hit this issue but don't have clear information.

Thanks,  
Ashley

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [September 8, 2017, 8:58pm UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/6 "2017-09-08T20:58:08Z")

</div>

Ok let's start from scratch here.

For the geoip filter you have here;

> [@ashleyl](#):
>
> geoip {  
> source =\> "clientip"  
> target =\> “geoip"  
> database =\> “/etc/logstash/GeoLiteCity.dat"  
> add\_field =\> [“[geoip][coordinates]”, “%{[geoip][longitude]}” ]  
> add\_field =\> [“[geoip][coordinates]”, “%{[geoip][latitude]}” ]  
> }

All you need is;

```auto
geoip {
  source => "clientip"
  target => “geoip"
}

```

So remove the rest.

However looking at your grok, there is no `clientip` field that is being parsed from the the message?

---

<div class="post-metadata">

### Author: ![ashleyl](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@ashleyl](https://discuss.elastic.co/u/ashleyl)
#### Post date: [September 11, 2017, 6:18am UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/7 "2017-09-11T06:18:30Z")

</div>

I'm really sorry that I didn't attached full grok filter.  
And thank you for point out the quotation mark, it is revised.  
Below is the full 10-django-filter.conf I'm using right now.

filter {  
if [type] == "log" {  
grok {  
match =\> {"message" =\> '%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-(-|"%{WORD:method}) http:/%{URIPATH:path} HTTP/%{NUMBER:httpversion}"'}  
match =\> {"message" =\> '%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-"%{WORD:method} /%{GREEDYDATA:uri\_path} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:bytes}'}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{WORD:path\_name}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])- method: %{WORD:method}, path: %{URIPATH:path}, clientip: %{IPORHOST:clientip}, duration: %{NUMBER:duration\_seconds}"}  
match =\> {"message" =\> '%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-"%{WORD:method} / HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:bytes}'}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-(-|"%{WORD:method} %{URIPATH:path} HTTP/%{NUMBER:httpversion}") %{NUMBER:response} %{NUMBER:bytes}"}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate}([%{DATA:module}:%{NUMBER:line\_no}])([%{WORD:django\_module}:%{WORD:function\_name}])([%{LOGLEVEL:log\_level}])-%{WORD:method} %{URIPATH:path} HTTP/%{NUMBER:httpversion} %{NUMBER:response} %{NUMBER:bytes}"}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])- clientip: %{IPORHOST:clientip}, path: %{GREEDYDATA:uri\_path}"}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-clientip: %{IPORHOST:clientip}, path: %{GREEDYDATA:uri\_path}"}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-Invalid %{GREEDYDATA:Invalid}"}  
match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:logDate} ([%{DATA:module}:%{NUMBER:line\_no}]) ([%{WORD:django\_module}:%{WORD:function\_name}]) ([%{LOGLEVEL:log\_level}])-%{GREEDYDATA:uri\_path}"}  
overwrite =\> ["message"]  
}  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
}  
date {  
match =\> ["logDate", "yyyy-MM-dd HH:mm:ss,SSS"]  
timezone =\> "Asia/Taipei"  
target =\> "@timestamp"  
}  
}

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [September 11, 2017, 6:53am UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/8 "2017-09-11T06:53:56Z")

</div>

Please use code formatting, it makes it much easier to read 🙂

---

<div class="post-metadata">

### Author: ![ashleyl](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@ashleyl](https://discuss.elastic.co/u/ashleyl)
#### Post date: [September 11, 2017, 9:23am UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/9 "2017-09-11T09:23:06Z")

</div>

Sorry Please find below:

```
filter {
  if [type] == "log" {
    grok {
      match => {"message" => '%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-(-|\"%{WORD:method}) http:/%{URIPATH:path} HTTP/%{NUMBER:httpversion}\"'}
      match => {"message" => '%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-"%{WORD:method} /%{GREEDYDATA:uri_path} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:bytes}'}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate} (\[%{WORD:path_name}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])- method: %{WORD:method}, path: %{URIPATH:path}, clientip: %{IPORHOST:clientip}, duration: %{NUMBER:duration_seconds}"}
      match => {"message" => '%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-"%{WORD:method} / HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:bytes}'}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-(-|\"%{WORD:method} %{URIPATH:path} HTTP/%{NUMBER:httpversion}\") %{NUMBER:response} %{NUMBER:bytes}"}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate}(\[%{DATA:module}:%{NUMBER:line_no}\])(\[%{WORD:django_module}:%{WORD:function_name}\])(\[%{LOGLEVEL:log_level}\])-%{WORD:method} %{URIPATH:path} HTTP/%{NUMBER:httpversion} %{NUMBER:response} %{NUMBER:bytes}"}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])- clientip: %{IPORHOST:clientip}, path: %{GREEDYDATA:uri_path}"}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-clientip: %{IPORHOST:clientip}, path: %{GREEDYDATA:uri_path}"}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-Invalid %{GREEDYDATA:Invalid}"}
      match => {"message" => "%{TIMESTAMP_ISO8601:logDate} (\[%{DATA:module}:%{NUMBER:line_no}\]) (\[%{WORD:django_module}:%{WORD:function_name}\]) (\[%{LOGLEVEL:log_level}\])-%{GREEDYDATA:uri_path}"}
      overwrite => ["message"]
        }
  }
  geoip {
    source => "clientip"
    target => "geoip"
  }
  date {
    match => ["logDate", "yyyy-MM-dd HH:mm:ss,SSS"]
    timezone => "Asia/Taipei"
    target => "@timestamp"
  }
}
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 9, 2017, 9:23am UTC](https://discuss.elastic.co/t/til-map-failed-to-show-locations-in-map-error-the-database-provided-is-invalid-or-corrupted/99122/10 "2017-10-09T09:23:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
