# Unable to add geo\_point mapping with sub lat/lon properties

**URL:** <https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941>\
**Category:** Elasticsearch\
**Created:** [August 13, 2019, 1:09am UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941 "2019-08-13T01:09:19Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![r0bot85](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@r0bot85](https://discuss.elastic.co/u/r0bot85)\
**Post date:** [August 13, 2019, 1:09am UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/1 "2019-08-13T01:09:19Z")

</div>

Hello,  
Hopefully this is an easy answer but not a stupid question. I am fairly new to the Elastick Stack in general but learning my way around.

I am attempting to get a Coordinate Map visualization using the GeoIP data from RDP logins. I have the winlogbeat configured to send the data to logstash and logstash configured to do the geoip lookup on the source ip which is all working. I got that far following the guide here:

> **[Monitoring Windows Logons with Winlogbeat](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat)**
>
> How to use the Winlogbeat and Kibana to visualize logon events from Windows event logs.

However the Index Pattern does not contain a geo\_point field and only contains the latitude and longitude in 4 "number" type fields

geoip.latitude|number  
geoip.location.lat|number  
geoip.location.lon|number  
geoip.longitude|number

From the guide and from what i have read and determined i need to setup a new dymanic mapping called geoip.location of the geo\_point type containing the sub fields (2 of the ones above) but i have been unable to do so. I found some code below which seems close but fails.

PUT \_template/winlogbeat\_1  
{  
"order": 1,  
"template": "winlogbeat-\*",  
"mappings": {  
"_default_": {  
"properties": {  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "float" },  
"longitude" : { "type" : "float" }  
}  
}  
}  
}  
}  
}

Thanks,  
Daryl

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 14, 2019, 7:35am UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/2 "2019-08-14T07:35:47Z")

</div>

can you explain exactly what you refer to when it 'fails'? in your above post? Do you get an exception? Do you get an error when applying the template or do you get an error when indexing the document?

Also note that creating a template does not mean it is applied immediately. You have to create a new index first in order for this to be applied.

---

<div class="post-metadata">

**Author:** ![r0bot85](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@r0bot85](https://discuss.elastic.co/u/r0bot85)\
**Post date:** [August 14, 2019, 3:16pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/3 "2019-08-14T15:16:01Z")

</div>

Of source I will explain more sorry, when I made the post I was 3 hours into trying to figure this out and getting frustrated lol.

When i attempt to run that code to create the template via the console I get the following response.

 ![com%20-%20Remote%20Desktop%20Connection](https://us1.discourse-cdn.com/elastic/original/3X/b/4/b460534b43399b81ef6da2ca0f4fc3f58ed99f99.png)

Here is how i configured the logstash.conf, it was slightly different than the walkthrough but needed as per the JSON field I had coming in that contained the source IP.

 ![mycre%20-%20Console%20Session](https://us1.discourse-cdn.com/elastic/original/3X/9/8/98f92a68aaf290950ab58a3b1d40d9ddc349df02.png)

Here you can see the geoip data that logstash is bringing into the JSON for the logs.

 ![com%20-%20Remote%20Desktop%20Connection](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aea6e0b0ec05d8dc6f027267aebe706c3b034d66.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 15, 2019, 7:08am UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/4 "2019-08-15T07:08:31Z")

</div>

can you please paste the snippets using markdown, the images are super hard to read and search and grep through. Thanks.

What Elasticsearch version are you using? Remember that from version 7 onwards there are no types anymore and make sure you pick the right version in the documentation as well.

---

<div class="post-metadata">

**Author:** ![r0bot85](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@r0bot85](https://discuss.elastic.co/u/r0bot85)\
**Post date:** [August 15, 2019, 3:44pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/5 "2019-08-15T15:44:32Z")

</div>

Sorry about that, appreciate your help Alexander.

I am on version Kibana 7.3.0 and the latest winlogbeat/logstash from about 6 days ago.

logstash.conf

```
input {
  beats {
   port => 5044
   type => "log"
  }
}

filter {
  geoip {
    source => "[source][ip]"
  }
}

output {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+yyyy.ww}"
    document_type => "%{[@metadata][type]}"
  }
}

```

Current index pattern is "winlogbeat-\*"

Error message when running the PUT \_template command

```
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "Root mapping definition has unsupported parameters: [_default_ : {properties={geoip={dynamic=true, properties={ip={type=ip}, latitude={type=float}, location={type=geo_point}, longitude={type=float}}}}}]"
      }
    ],
    "type": "mapper_parsing_exception",
    "reason": "Failed to parse mapping [_doc]: Root mapping definition has unsupported parameters: [_default_ : {properties={geoip={dynamic=true, properties={ip={type=ip}, latitude={type=float}, location={type=geo_point}, longitude={type=float}}}}}]",
    "caused_by": {
      "type": "mapper_parsing_exception",
      "reason": "Root mapping definition has unsupported parameters: [_default_ : {properties={geoip={dynamic=true, properties={ip={type=ip}, latitude={type=float}, location={type=geo_point}, longitude={type=float}}}}}]"
    }
  },
  "status": 400
}

```

As far as the statement about there not being a type i dont understand, because when i go to make a new Coordinate Map visulization it says

`The index pattern winlogbeat-* does not contain any of the following compatible field types: geo_point`

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 16, 2019, 12:33pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/6 "2019-08-16T12:33:52Z")

</div>

I can't see the template you are trying to put, but try to omit the `_doc` part of the template and see if that works. If not, please paste the full command of putting the template here as well in a snippet.

---

<div class="post-metadata">

**Author:** ![r0bot85](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@r0bot85](https://discuss.elastic.co/u/r0bot85)\
**Post date:** [August 16, 2019, 3:06pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/7 "2019-08-16T15:06:04Z")

</div>

It is the one from the article, don't think it has a \_doc part that i see

```
PUT _template/winlogbeat_1
{
  "order": 1,
  "template": "winlogbeat-*",
  "mappings": {
    "_default_": {
      "properties": {
        "geoip" : {
          "dynamic": true,
          "properties" : {
            "ip": { "type": "ip" },
            "location" : { "type" : "geo_point" },
            "latitude" : { "type" : "float" },
            "longitude" : { "type" : "float" }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 19, 2019, 6:45am UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/8 "2019-08-19T06:45:26Z")

</div>

I think we're back to good now, took some time to properly refresh...

---

<div class="post-metadata">

**Author:** ![r0bot85](https://avatars.discourse-cdn.com/v4/letter/r/e47c2d/32.png) [@r0bot85](https://discuss.elastic.co/u/r0bot85)\
**Post date:** [August 19, 2019, 3:03pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/9 "2019-08-19T15:03:07Z")

</div>

Alexander,  
I am not sure what you mean, was the guide updated? The commands in the guide look the same so i dont know what may have changed or "refreshed".

Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 19, 2019, 3:46pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/10 "2019-08-19T15:46:36Z")

</div>

sorry, this reply was not meant for this thread...

try to remove the `_default_` field from the above JSON

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2019, 3:46pm UTC](https://discuss.elastic.co/t/unable-to-add-geo-point-mapping-with-sub-lat-lon-properties/194941/11 "2019-09-16T15:46:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
