# Unable to put dstip\_geoip.location on map

**URL:** <https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073>\
**Category:** Kibana\
**Created:** [January 18, 2017, 7:30pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073 "2017-01-18T19:30:15Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 18, 2017, 7:30pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/1 "2017-01-18T19:30:15Z")

</div>

In my Logstash.conf file I have the following to parse my sonicwall logs, which is working well and I am getting good data thats geo-coded on the fly, but when using kibana and trying to create a tile map the field doesn't show up. How do I go about getting this field in there? My logstash config is below.

#logstash.conf

input {  
udp {  
type =\> sonicwall  
codec =\> plain {  
charset =\> "ISO-8859-1"  
}  
port =\> 514  
}  
}

filter {  
if [type] == "sonicwall" {

```
kv {
    exclude_keys => ["<129>id", "<132>id", "<133>id","<134>id", "af_polid", "af_service", "app", "appid", "code", "fw", "m", "op", "sn"]
}

date {
    match => ["time", "yyyy-MM-dd HH:mm:ss z", "yyyy-MM-dd HH:mm:ss"]
}

if [src] {
    grok {
        match => { 
            "src" => [
                "%{IP:srcip}:%{INT:srcport}:%{DATA:srcint}:%{GREEDYDATA:srcname}",
                "%{IP:srcip}:%{INT:srcport}:%{DATA:srcint}",
                "%{IP:srcip}::%{DATA:srcint}",
                ":%{INT:srcport}"
            ]  
        }
    }
}

if [dst] {
    grok {
        match => { 
            "dst" => [ 
                "%{IP:dstip}:%{INT:dstport}:%{DATA:dstint}:%{GREEDYDATA:dstinfo}",
                "%{IP:dstip}:%{INT:dstport}:%{DATA:dstint}",
                "%{IP:dstip}::%{DATA:dstint}",
                ":%{INT:dstport}"
            ]
        }
    }
}

# Sanitize fields with \r after recent firmware update
mutate {
    gsub => [
        "sent", "\r", "",
        "rcvd", "\r", "",
        "cdur", "\r", "",
        "spkt", "\r", "",
        "rpkt", "\r", "",
        "proto", "\r", ""
    ]
}

# Assign network tags based on IP
if [dstip] {
    cidr {
        add_tag => ["dstip-private"]
        address => ["%{dstip}"]
        network => ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"]
    }                
    
    # Parse GeoIP info
    if "dstip-private" not in [tags] {
        geoip {
            source => "dstip"
            target => "dstip_geoip"
            fields => ["country_name", "region_name", "city_name", "location"]
               }
    }
}

# Replace srcname with srcip if srcname does not exist
if ![srcname] and [srcip] {
    mutate {
        replace => { "srcname" => "%{srcip}" }
    }
}	

# Replace dstname with dstinfo or dstip if dstname does not exist
if ![dstname] and [dstinfo] {
    mutate {
        replace => { "dstname" => "%{dstinfo}" }
    }
} else if ![dstname] and [dstip] {
    mutate {
        replace => { "dstname" => "%{dstip}" }
    }
}	

mutate {
    lowercase => ["msg", "appName", "sess", "fw_action", "srcint", "dstint", "Category"]
    remove_field => ["src", "dst", "dstinfo", "message", "time"]
    
}	    

```

}  
}

output {  
elasticsearch { hosts =\> ["localhost:9201"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [January 18, 2017, 8:01pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/2 "2017-01-18T20:01:31Z")

</div>

Hi Frank,

If you look at your index pattern fields in the Management \> Index Patterns section of Kibana do you see your expected geo field as a `geo_point` type?

Example:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b796167c8bd0ed442d34cb7aceca87fda30ee473.png)

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 20, 2017, 4:19pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/3 "2017-01-20T16:19:30Z")

</div>

I see it as NUMBER type - how do I change that?

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 20, 2017, 4:21pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/4 "2017-01-20T16:21:07Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/2X/d/db21a629fd06f16b39f721e698d11267bf22b2c6.png)

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [January 20, 2017, 7:31pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/5 "2017-01-20T19:31:14Z")

</div>

Hi Frank,  
I'm going to refer you to some logstash posts like;

> [@Add Geopoint based off of parsed value to logstash config](https://discuss.elastic.co/t/add-geopoint-based-off-of-parsed-value-to-logstash-config/26580/2):
>
> Is that what's in your configuration file? Because it barely resembles Logstash's configuration file syntax. You need something like this: filter { if [XCent] and [YCent] { mutate { add\_field =\> { "[location][lat]" =\> "%{XCent}" "[location][lon]" =\> "%{YCent}" } } mutate { convert =\> { "[location][lat]" =\> "float" "[location][lon]" =\> "float" } } } }

You can also search that logstash forum for `geopoint` to find other posts about it.

If you're still having problems, please post another question there. Also, please include the logstash version you're using as things do change from release to release.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [January 20, 2017, 7:49pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/6 "2017-01-20T19:49:09Z")

</div>

Hi Frank,  
I chatted with a Logstash expert and he said, you would need to delete your index, then either name your field (target) to `geoip.location` (which logstash maps to a geopoint), or add the mapping for your `dstip_geoip` to be a geopoint.

Lee

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 20, 2017, 8:39pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/7 "2017-01-20T20:39:40Z")

</div>

How do I add the mapping for dstip\_geoip to be a geopoint?

I assume I have to modify this code # Parse GeoIP info

if "dstip-private" not in [tags] {  
geoip {  
source =\> "dstip"  
target =\> "dstip\_geoip"  
fields =\> ["country\_name", "region\_name", "city\_name", "location"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [January 23, 2017, 2:55am UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/8 "2017-01-23T02:55:49Z")

</div>

Which ES version are you using?  
If you are on ES 2.x, you can install `elasticsearch-kopf` plugin to add/manage index mapping templates. For 5.x, you can use Developer Tool/Sense on Kibana

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 23, 2017, 3:57am UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/9 "2017-01-23T03:57:58Z")

</div>

I am using 5.x, how do you use "sense" I have developer tools installed

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [January 23, 2017, 6:17am UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/10 "2017-01-23T06:17:23Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 24, 2017, 5:22pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/11 "2017-01-24T17:22:17Z")

</div>

I've reviewed the document, and I don't mind rebuilding my index - but I'm still unsure how to rename the field

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 30, 2017, 8:38pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/12 "2017-01-30T20:38:59Z")

</div>

Someone please help - I really want to get this working. I've installed developer tools and I know I have to make a curl request with something like this

PUT /attractions  
{  
"mappings": {  
"restaurant": {  
"properties": {  
"name": {  
"type": "string"  
},  
"location": {  
"type": "geo\_point"  
}  
}  
}  
}  
}

but don't know exactly what to put in it.

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [January 31, 2017, 5:57pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/13 "2017-01-31T17:57:27Z")

</div>

This is how I process IIS log and add GeoIP data [http://www.secureict.info/2016/07/elastic-stack-process-iis-logs.html](http://www.secureict.info/2016/07/elastic-stack-process-iis-logs.html).

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 31, 2017, 7:17pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/14 "2017-01-31T19:17:10Z")

</div>

thank you anhlqn

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [January 31, 2017, 9:03pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/15 "2017-01-31T21:03:51Z")

</div>

this is why my current index looks like

> <https://gist.github.com/BustedSec/19f4b566481f8c2ebc595a7a5e484ecd>

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [January 31, 2017, 11:53pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/16 "2017-01-31T23:53:32Z")

</div>

First of all, are you familiar with using Dev tool to manage index templates? There are a few things you should know:

- Create a new index template
- Update existing index template
- Update mappings for existing indexes (add more field mappings actually, you can't change existing mappings on indexes AFAIK)

On your current indexes a few things that I can tell:

I see 3 data types: "8", "12", and "sonicwall". It could be caused by wrong grok patterns. Don't send data from Logstash to Elasticsearch until you are sure the data are correctly formatted/transformed as you want. Use either stdout or sending out to local file to test and tune the LS config

Your dstip\_geoip.location still has wrong data type

```auto
 "dstip_geoip": {
            "properties": {
              "city_name": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "country_name": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "location": {
                "type": "float"
              },
              "region_name": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          }

```

A few things you can do to get this work.

1. Use stdout in LS config and see why data has `"type": "8"` and `"type": "12"`. All data should have `"type": "sonicwall"` so that your filters can pick up all messages and process correctly
2. Delete existing indexes if you can. If not, use a different index pattern to start fresh. Something like `sonicwall-%{+YYYY.MM.DD}` will do. [Sample LS config](https://github.com/anhlqn/elastic/blob/master/logstash/sonicwall-logstash-filter.txt)
3. Add [this mapping template](https://github.com/anhlqn/elastic/blob/master/elasticsearch/mapping-templates/sonicwall-syslog.json) to your ES cluster using Dev tool. Data types should be updated to match v5.x since this mapping template is for 2.x
4. Send data into ES and see if the `dstip_geoip.location` field is mapped correctly as `geo_point`.

---

<div class="post-metadata">

**Author:** ![Frank\_Trezza](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Frank\_Trezza](https://discuss.elastic.co/u/Frank_Trezza)\
**Post date:** [February 1, 2017, 3:03pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/17 "2017-02-01T15:03:43Z")

</div>

On step 3-  
how do I find the 2.x data type equivalents in 5.x - I looked at [https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-types.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-types.html) but all the "type" sections seem to be listed there that are in the linked 2.0 template

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [February 1, 2017, 9:32pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/18 "2017-02-01T21:32:03Z")

</div>

The main difference is string type. Text and keyword now replace string type.

2.x mapping

```auto
"dstname": {
          "include_in_all": true,
          "index": "not_analyzed",
          "type": "string"
        },

```

5.x mapping

```auto
"dstname": {
          "include_in_all": true,
          "type": "keyword"
        },

```

I haven't used 5.x a lot so I don't know all the breaking changes in 5.x

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2017, 9:32pm UTC](https://discuss.elastic.co/t/unable-to-put-dstip-geoip-location-on-map/72073/19 "2017-03-01T21:32:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
