# Unable to create "Maps" visualization - Getting "Selected index pattern does not contain source and destination fields."

**URL:** <https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683>\
**Category:** Kibana\
**Created:** [June 22, 2021, 5:10pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683 "2021-06-22T17:10:08Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 22, 2021, 5:10pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/1 "2021-06-22T17:10:08Z")

</div>

I'm unable to create "Maps" visualization. I get the error "Selected index pattern does not contain source and destination fields." I'm on version 7.13.2 ELK

I used geoip to define the source and destination IP fields as below :-

```auto
 if "BackendIP" not in [tags]
                {
        geoip
                {
                        target => "Src_IP"
                        source => "Fwd_Client_IP"
                        tag_on_failure => ["IP-lookup-failed"]

                }
        geoip
                {
                        target => "Dst_IP"
                        source => "Forward_IP"
                        tag_on_failure => ["IP-lookup-failed"]
                }

```

I read some articles about creating a geo\_point , but since geoip already creates "lon" and "lat" values, doesn't already have what it needs to create a geo\_point? If not, could you help me how to create a geo\_point ? can it created on logstash config ? or elasticsearch ?

i'm new to ELK and in a learning phase .

 ![Screen Shot 2021-06-22 at 10.36.53 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27f17c4bd71b268e454f29587593ff243d7e159b.jpeg)

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 22, 2021, 7:24pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/2 "2021-06-22T19:24:36Z")

</div>

What is the [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html) output for the index. The lat and lon fields must be mapped as [geo\_point](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html) in order to be used in the maps application. If they are just mapped as numbers then you do not have a spatial index and can not use the data in maps.

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 23, 2021, 12:56pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/3 "2021-06-23T12:56:29Z")

</div>

Hmm, seems the mapping is missing from my index . How do i create the geo\_point ? is it done on logstash? via config ?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 23, 2021, 1:33pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/4 "2021-06-23T13:33:28Z")

</div>

After index creation and before inserting documents, add geo\_point mapping to your index by running a command like the one below in Kibana =\> dev tools =\> console.

```auto
PUT your_index_name/_mapping
{
  "properties": {
    "location": {
      "type": "geo_point"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 23, 2021, 2:08pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/5 "2021-06-23T14:08:19Z")

</div>

awesome 🙂 I was able to create . But i still get same error "Selected index pattern does not contain source and destination fields." , seems i'm missing something .

````auto
"timezone": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        },
        "line_type": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "location": {
          "type": "geo_point"
        }
      }
    }
  }
}```
````

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 23, 2021, 2:11pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/6 "2021-06-23T14:11:56Z")

</div>

i changed "location" to "geolocation" and it worked , the error has disappeared. However it shows that no results , even after ingesting some logs . Does changing from location to geolocation have some significance ?

```auto
PUT logstash_geo_ghost1/_mapping
{
    "properties":{
      "geolocation": {
        "type":"geo_point"
      }
    }

```

 ![Screen Shot 2021-06-23 at 7.46.01 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1fa190f83664d750983007a6a5a84e022297c1e1.jpeg)

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 23, 2021, 5:04pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/7 "2021-06-23T17:04:00Z")

</div>

any update ? No data is shown even after processing some logs

 ![Screen Shot 2021-06-23 at 10.34.40 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/4/544a8b96ac9dcbbe2856c4c579ed4ce1a242ed9c.jpeg)

logstash parses correctly , source and destination IPs are visible

```auto
{
                     "Src_IP" => {
         "country_code3" => "FR",
           "postal_code" => "13000",
              "location" => {
            "lat" => 43.2951,
            "lon" => 5.3861
        },
                    "ip" => "2.21.85.4",
         "country_code2" => "FR",
        "continent_code" => "EU",
              "latitude" => 43.2951,
           "region_name" => "Bouches-du-Rhône",
          "country_name" => "France",
             "city_name" => "Marseille",
           "region_code" => "13",
             "longitude" => 5.3861,
              "timezone" => "Europe/Paris"
    },
                     "Dst_IP" => {
         "country_code3" => "IN",
           "postal_code" => "600001",
              "location" => {
            "lat" => 12.8996,
            "lon" => 80.2209
        },
                    "ip" => "23.57.75.218",
         "country_code2" => "IN",
        "continent_code" => "AS",
              "latitude" => 12.8996,
           "region_name" => "Tamil Nadu",
          "country_name" => "India",
             "city_name" => "Chennai",
           "region_code" => "TN",
             "longitude" => 80.2209,
              "timezone" => "Asia/Kolkata"

```

Output section :

```auto
output
        {
                elasticsearch
                                {
                                        hosts => ["172.27.205.251:9200"]
                                        index => "logstash_geo"
                                }

                stdout{}
        }

```

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [June 24, 2021, 6:07pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/8 "2021-06-24T18:07:08Z")

</div>

@Shreesh_Narayanan

The source-and-destination selection in those two dropdowns should both be a _different_ field of type `geo_point`. It looks like you are using the same field `location`.

Also a few other things to check:

- make sure that the data is indexed correctly (e.g. use Discover to check you have two `geo_point` fields with actual lat/lons,
- make sure the time-filter (top right, in Kibana) is large enough for your data-range

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 25, 2021, 12:49pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/9 "2021-06-25T12:49:58Z")

</div>

oh okay, makes sense . To create geo\_point for source and destination, i need to have the lon/lat values in a single field,correct ? how do i create it ? i tried adding a field inside geoip such as the one below , but it did not work .should i use a separate mutate filter for this ?

```auto
geoip
                {
                        target => "Dst_IP"
                        source => "Forward_IP"
                        tag_on_failure => ["IP-lookup-failed"]
                        add_field => {"Destination_geo" => "[geoip][location][lon]","[geoip]location][lat]"]

                }

```

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 29, 2021, 10:49am UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/10 "2021-06-29T10:49:13Z")

</div>

I managed to get the source and destination lat/lon points in the same field

```auto
     "destinationip" => "42.106.161.193",
          "sourceip" => "1.1.1.1",
    "sourcelocation" => "143.2104,-33.494",
      "destlocation" => "88.3832,22.518",

```

How should the geo\_point be created now ? i think it should be for source and destination .

```auto

PUT logstashgeotest/_mapping
{
  "properties":{
    "sourcelocation":{
      "type": "geo_point"
    }
  }
}

```

I tried the above, but elasticsearch (done via dev console) gave an error

```auto

{
  "error" : {
    "root_cause" : [
      {
        "type" : "illegal_argument_exception",
        "reason" : "mapper [sourcelocation] cannot be changed from type [text] to [geo_point]"
      }
    ],
    "type" : "illegal_argument_exception",
    "reason" : "mapper [sourcelocation] cannot be changed from type [text] to [geo_point]"
  },
  "status" : 400
}

```

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 29, 2021, 12:51pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/11 "2021-06-29T12:51:54Z")

</div>

You can not change a field's mapping. You will need to delete the index and then use the correct mappings.

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [June 30, 2021, 2:29pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/12 "2021-06-30T14:29:25Z")

</div>

thank you . it works now .

sample config where lat and lon values are in the same field and converted to geo point , this conversion was done before any data was pushed/ingested into it

```auto
geoip
{
add_tag => ["geoip"]
source => "sourceip"
target => "SRC_ip"
#fields => ["ip", "country_code2", "country_name", "latitude", "longitude"]
}
geoip 
{
add_tag => ["geoip"]
source => "destinationip"
target => "Dest_IP"
}
mutate 
{
add_field => ["sourcelocation","%{[SRC_ip][longitude]}","tmplat","%{[SRC_ip][latitude]}"]
add_field => ["destlocation","%{[Dest_IP][longitude]}","tmplatdst","%{[Dest_IP][latitude]}"]
}
mutate
{
merge => ["sourcelocation","tmplat"] 
merge => ["destlocation","tmplatdst"]
}
mutate
{
convert => ["sourcelocation","float"]
convert => ["destlocation","float"]
}
mutate {
remove_field => ["tmplat","tmplatdst"]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 2:29pm UTC](https://discuss.elastic.co/t/unable-to-create-maps-visualization-getting-selected-index-pattern-does-not-contain-source-and-destination-fields/276683/13 "2021-07-28T14:29:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
