# Unable to create Region Map Visualization

**URL:** <https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815>\
**Category:** Kibana\
**Created:** [July 12, 2018, 6:34pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815 "2018-07-12T18:34:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 12, 2018, 6:34pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815/1 "2018-07-12T18:34:26Z")

</div>

Hi all,

I am trying to create a Region Map visualization on Kibana using the IP addresses present in the log. I downloaded a sample of apache access log from the following link [Apache access log](https://raw.githubusercontent.com/elastic/examples/master/Common%20Data%20Formats/apache_logs/apache_logs)

I was able to successfully ingest the file's log data into Logstash and parse the log data into Elasticsearch. These are the fields in the index pattern created.

 ![Screenshot%20(4)](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c82c313c92ab10a0261ae93ffd42819b85acc6db.png)

The json response of the same looks like this after executing the query `GET logstash-2018.07.07/_mapping`

```
{
  "logstash-2018.07.07": {
    "mappings": {
      "doc": {
        "dynamic_templates": [
          {
            "message_field": {
              "path_match": "message",
              "match_mapping_type": "string",
              "mapping": {
                "norms": false,
                "type": "text"
              }
            }
          },
          {
            "string_fields": {
              "match": "*",
              "match_mapping_type": "string",
              "mapping": {
                "fields": {
                  "keyword": {
                    "ignore_above": 256,
                    "type": "keyword"
                  }
                },
                "norms": false,
                "type": "text"
              }
            }
          }
        ],
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "keyword"
          },
          "geoip": {
            "dynamic": "true",
            "properties": {
              "ip": {
                "type": "ip"
              },
              "latitude": {
                "type": "half_float"
              },
              "location": {
                "type": "geo_point"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          },
          "host": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "message": {
            "type": "text",
            "norms": false
          },
          "path": {
            "type": "text",
            "norms": false,
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      },
      "_default_": {
        "dynamic_templates": [
          {
            "message_field": {
              "path_match": "message",
              "match_mapping_type": "string",
              "mapping": {
                "norms": false,
                "type": "text"
              }
            }
          },
          {
            "string_fields": {
              "match": "*",
              "match_mapping_type": "string",
              "mapping": {
                "fields": {
                  "keyword": {
                    "ignore_above": 256,
                    "type": "keyword"
                  }
                },
                "norms": false,
                "type": "text"
              }
            }
          }
        ],
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "keyword"
          },
          "geoip": {
            "dynamic": "true",
            "properties": {
              "ip": {
                "type": "ip"
              },
              "latitude": {
                "type": "half_float"
              },
              "location": {
                "type": "geo_point"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          }
        }
      }
    }
  }
}

```

I want to create a Region Map using the IP addresses to show the corresponding locations on the map. I tried doing, but I am unable to create any visualization. It only shows a blank map.

I've been trying very hard to create a map visualization. Can someone please help me out?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2018, 7:36pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815/2 "2018-07-12T19:36:13Z")

</div>

Do you have the right time period selected (to right) to make sure data will be visible?

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 12, 2018, 8:59pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815/3 "2018-07-12T20:59:12Z")

</div>

Yes, I did. It is still doesn't show up. Do I have to install additional plugins or change the configuration of logstash for GeoIP?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2018, 9:00pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815/4 "2018-07-12T21:00:50Z")

</div>

Can you see the documents in Discover?

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [July 12, 2018, 10:18pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815/5 "2018-07-12T22:18:32Z")

</div>

I followed this tutorial [GeoIP](https://www.digitalocean.com/community/tutorials/how-to-map-user-location-with-geoip-and-elk-elasticsearch-logstash-and-kibana)

However, I did not use Filebeat as I am directly ingesting apache files into logstash. Is the below configuration right?

```
input {
  file {
    path => "E:\elk\logstash\apache_logs"
    start_position => "beginning"
  }
}

filter {
  grok {
    match => { "message" => "%{COMBINEDAPACHELOG}" }
  }
  geoip {
      source => "clientip"
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
  }
}

```

What should my clientip be?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2018, 10:18pm UTC](https://discuss.elastic.co/t/unable-to-create-region-map-visualization/139815/6 "2018-08-09T22:18:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
