# Unable to find source.geo.location in index pattern logstash-\*

**URL:** <https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496>\
**Category:** Elasticsearch\
**Created:** [February 17, 2021, 12:10am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496 "2021-02-17T00:10:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronnie\_Raraihuru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie_raraihuru/32/48088_2.png) [@Ronnie\_Raraihuru](https://discuss.elastic.co/u/Ronnie_Raraihuru)\
**Post date:** [February 17, 2021, 12:10am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496/1 "2021-02-17T00:10:17Z")

</div>

Got the above error when trying to view map under Security\>Network in Elastic.

**Index mapping**

```
  "mappings" : {

	"geoip" : {
          "dynamic" : "true",
          "properties" : {
            "city_name" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "continent_code" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "country_code2" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "country_code3" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "country_name" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "dma_code" : {
              "type" : "long"
            },
            "ip" : {
              "type" : "ip"
            },
            "latitude" : {
              "type" : "half_float"
            },
            "location" : {
              "type" : "geo_point"
            },
            "longitude" : {
              "type" : "half_float"
            },
            "postal_code" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "region_code" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "region_name" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            },
            "timezone" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              },
              "norms" : false
            }
          }
        }
		
	  }
```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 17, 2021, 1:11am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496/2 "2021-02-17T01:11:25Z")

</div>

Hi @Ronnie_Raraihuru

Question are you ingesting from one of the beats modules through logstash or is this just a custom source? I ask because if it is a module I have one suggestion, if it is a custom source then I will have different device.

I can tell you in short you are ingesting data not in the correct fields if you want them to show up in in the security app the need to be in the right fields

See [Here](https://www.elastic.co/guide/en/security/current/siem-field-reference.html#siem-field-reference)

Your mapping is missing the [network fields and location fields](https://www.elastic.co/guide/en/security/current/siem-field-reference.html#siem-network-fields)

Your mapping is not correction the geoip is at the wrong level these should be at the top level.

- `@timestamp`
- `destination.geo.location` (required for displaying [map data](https://www.elastic.co/guide/en/security/current/conf-map-ui.html))
- `destination.ip`
- `source.geo.location` (required for displaying map data)
- `source.ip`

---

<div class="post-metadata">

**Author:** ![Ronnie\_Raraihuru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie_raraihuru/32/48088_2.png) [@Ronnie\_Raraihuru](https://discuss.elastic.co/u/Ronnie_Raraihuru)\
**Post date:** [February 17, 2021, 1:30am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496/3 "2021-02-17T01:30:36Z")

</div>

Thanks Stephen ,  
I am ingesting through logstash. ( Filebeat \>Logstash\>Elastic)  
How to i add the destination.geo.location and source.geo.location to my current mapping ?

Hear from you.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 17, 2021, 1:40am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496/4 "2021-02-17T01:40:30Z")

</div>

Are you using a predefined module? like ngnix or PANOS etc? You did not answer... it may be much simpler.

Otherwise, You need to create a mapping ahead of time something like the following and you should use an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html) so ever index automatically get the mapping.

Something like this... this should get you started, follow the pattern and the docs

```
PUT _index_template/my-data
{
  "index_patterns": [
    "my-data-*"
  ],
  "template": {
    "settings": {
      "number_of_shards": 1,
      "lifecycle": {
        "name": "my-data",
        "rollover_alias": "my-data"
      }
    },
    "aliases": {},
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword"
            }
          }
        },
        "event": {
          "properties": {
            "dataset": {
              "type": "keyword"
            },
            "category": {
              "type": "keyword"
            }
          }
        },
        "host": {
          "properties": {
            "name": {
              "type": "keyword"
            },
            "ip": {
              "type": "ip"
            },
            "os": {
              "properties": {
                "name": {
                  "type": "keyword"
                },
                "version": {
                  "type": "keyword"
                }
              }
            }
          }
        },
        "message": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword"
            }
          }
        },
        "source": {
          "properties": {
            "ip": {
              "type": "ip"
            },
            "geo": {
              "properties": {
                "location": {
                  "type": "geo_point"
                }
              }
            }
          }
        },
        "destination": {
          "properties": {
            "ip": {
              "type": "ip"
            },
            "geo": {
              "properties": {
                "location": {
                  "type": "geo_point"
                }
              }
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Ronnie\_Raraihuru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ronnie_raraihuru/32/48088_2.png) [@Ronnie\_Raraihuru](https://discuss.elastic.co/u/Ronnie_Raraihuru)\
**Post date:** [February 17, 2021, 1:53am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496/5 "2021-02-17T01:53:42Z")

</div>

Thanks Stephen ,  
Have not used a predefined module.  
Will get started with the patterns you have provide like wise for the index template

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2021, 1:53am UTC](https://discuss.elastic.co/t/unable-to-find-source-geo-location-in-index-pattern-logstash/264496/6 "2021-03-17T01:53:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
