# Two GeoIP sources and target locations

**URL:** <https://discuss.elastic.co/t/two-geoip-sources-and-target-locations/104184>\
**Category:** Logstash\
**Created:** [October 17, 2017, 6:08am UTC](https://discuss.elastic.co/t/two-geoip-sources-and-target-locations/104184 "2017-10-17T06:08:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mwelninski](https://avatars.discourse-cdn.com/v4/letter/m/ec9cab/32.png) [@mwelninski](https://discuss.elastic.co/u/mwelninski)\
**Post date:** [October 17, 2017, 6:08am UTC](https://discuss.elastic.co/t/two-geoip-sources-and-target-locations/104184/1 "2017-10-17T06:08:53Z")

</div>

Hello, let me first say that I appreciate any help that can be provided around this issue I have been fighting with.

Background:  
I am loading in firewall logs into a 5.6 ELK Stack running on Windows. The information is mainly been filtered into .csv format and everything seems to being searchable and working as I would hope. The last thing I would like to do is have the source address and destination address geo-locations be displayed in the map coordinates visualization.

I've tried quite a bit to get the geoip filter to work as needed. After reading through the Logstash filter plugin documentation for the geoip more extensively I discovered that by not supplying a target for filter I could get the geoip default target to work with the Kibana visualization as this would fix the target to be of type geo\_point.

The problem I am still experiencing is, I am unable to filter in a the second bit of information. From previous forum/questions that have been posted on this website, I did find that supposedly by adding another index template i can fix this issue.

I should say that I do not really have any knowledge or experience working with elasticsearch. So it would be very helpful if someone give give a few step by step instructions on how I can do this. I have visited Kibana's Dev-Tools page and tried running the following query but i continue to get this same error.

query:  
GET:  
GET \_template/\*

Response:  
{  
"logstash": {  
"order": 0,  
"version": 50001,  
"template": "logstash-_",  
"settings": {  
"index": {  
"refresh\_interval": "5s"  
}  
},  
"mappings": {  
"default": {  
"dynamic\_templates": [  
{  
"message\_field": {  
"path\_match": "message",  
"mapping": {  
"norms": false,  
"type": "text"  
},  
"match\_mapping\_type": "string"  
}  
},  
{  
"string\_fields": {  
"mapping": {  
"norms": false,  
"type": "text",  
"fields": {  
"keyword": {  
"ignore\_above": 256,  
"type": "keyword"  
}  
}  
},  
"match\_mapping\_type": "string",  
"match": "_"  
}  
}  
],  
"\_all": {  
"norms": false,  
"enabled": true  
},  
"properties": {  
"@timestamp": {  
"include\_in\_all": false,  
"type": "date"  
},  
"geoip": {  
"dynamic": true,  
"properties": {  
"ip": {  
"type": "ip"  
},  
"latitude": {  
"type": "half\_float"  
},  
"location": {  
"type": "geo\_point"  
},  
"longitude": {  
"type": "half\_float"  
}  
}  
},  
"@version": {  
"include\_in\_all": false,  
"type": "keyword"  
}  
}  
}  
},  
"aliases": {}  
}  
}

I believe from what I've read that I need to mimic this section and add it on to this template:  
"geoip": {  
"dynamic": true,  
"properties": {  
"ip": {  
"type": "ip"  
},  
"latitude": {  
"type": "half\_float"  
},  
"location": {  
"type": "geo\_point"  
},  
"longitude": {  
"type": "half\_float"  
}  
}  
},

Now I think I need to simply run this code below:  
PUT:  
PUT \_template/geo\_src  
{  
"geo\_src": {  
"dynamic": true,  
"properties": {  
"ip": {  
"type": "ip"  
},  
"latitude": {  
"type": "half\_float"  
},  
"location": {  
"type": "geo\_point"  
},  
"longitude": {  
"type": "half\_float"  
}  
}  
},  
}

But I am receiving this error:  
Error:  
{  
"error": {  
"root\_cause": [  
{  
"type": "parse\_exception",  
"reason": "Failed to parse content to map"  
}  
],  
"type": "parse\_exception",  
"reason": "Failed to parse content to map",  
"caused\_by": {  
"type": "json\_parse\_exception",  
"reason": "Unexpected character ('}' (code 125)): was expecting double-quote to start field name\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@7e8c4b04; line: 19, column: 2]"  
}  
},  
"status": 400  
}

Am I completely misunderstanding what I need to do to fix this issue? Thank you to everyone in advance.

-Marcin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2017, 6:09am UTC](https://discuss.elastic.co/t/two-geoip-sources-and-target-locations/104184/2 "2017-11-14T06:09:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
