# Using custom target for geoip filter, how to update Elasticsearch template?

**URL:** <https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442>\
**Category:** Logstash\
**Created:** [March 24, 2018, 3:20pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442 "2018-03-24T15:20:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![omeugdoj](https://avatars.discourse-cdn.com/v4/letter/o/b77776/32.png) [@omeugdoj](https://discuss.elastic.co/u/omeugdoj)\
**Post date:** [March 24, 2018, 3:20pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/1 "2018-03-24T15:20:35Z")

</div>

I am enriching my firewall logs with GeoIP information for the source and destination IPs. Because of that, I have to use custom target field names: `src_geoip` and `dst_geoip`.

This is the relevant part for my filter:

```auto
      geoip { source => "source" target => "src_geoip" }
      geoip { source => "destination" target => "dst_geoip" }

```

But in my index, these fields aren't the correct type for Kibana to display on a map using the lat/long.

The error message is:

> No Compatible Fields: The "myindex-\*" index pattern does not contain any of the following field types: geo\_point

How do I update the index so that it's the right type? The index is named `myindex-+{YYYY.MM.dd}` so it creates a new index daily. Do I have to update every index every day? Is there a way to set this for all future indices instead?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 6:07pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/2 "2018-03-24T18:07:51Z")

</div>

You need to create an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/indices-templates.html) that applies for that index pattern and contains the correct mappings for those fields.

---

<div class="post-metadata">

**Author:** ![omeugdoj](https://avatars.discourse-cdn.com/v4/letter/o/b77776/32.png) [@omeugdoj](https://discuss.elastic.co/u/omeugdoj)\
**Post date:** [March 24, 2018, 6:15pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/3 "2018-03-24T18:15:30Z")

</div>

Thank you. I have done it by creating the template for myindex-_, then deleting the existing myindex-_ indices. Now it creates an empty index for myindex-\<today's date\> I'm guessing from logstash but the index never fills. It's always sitting at 0 documents when I know events are being sent. I can't see any error message in the logstash or ES consoles. Why isn't it filling anymore?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 6:19pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/4 "2018-03-24T18:19:00Z")

</div>

Look in the Elasticseasrch and Logstash logs, preferably with debug mode enabled. If you have used a type in your index template that is different from what Logstash is sending, all indexing will fail as having 2 different types in an index is no longer allowed in Elasticsearch 6.x. Any type of mapping conflict could also cause indexing to fail.

---

<div class="post-metadata">

**Author:** ![omeugdoj](https://avatars.discourse-cdn.com/v4/letter/o/b77776/32.png) [@omeugdoj](https://discuss.elastic.co/u/omeugdoj)\
**Post date:** [March 24, 2018, 6:43pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/5 "2018-03-24T18:43:02Z")

</div>

Would that be in logstash's logs on ES's? I have turned on debug mode for logstash and I don't see any errors.

I don't know how to turn it on for ES, I don't know which logging facility there are or which one I want to look at.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 6:43pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/6 "2018-03-24T18:43:30Z")

</div>

It should be in the Logstash logs.

---

<div class="post-metadata">

**Author:** ![omeugdoj](https://avatars.discourse-cdn.com/v4/letter/o/b77776/32.png) [@omeugdoj](https://discuss.elastic.co/u/omeugdoj)\
**Post date:** [March 24, 2018, 6:46pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/7 "2018-03-24T18:46:59Z")

</div>

I don't see anything suspicious in there. Only that it does see the events coming in and processes them. No failures there. The document count in that index is still sitting at 0 though despite logstash receiving several per second.

--edit: I found the issue by looking into the dead\_letter\_queue logs. There was a mismatch for the type in some fields, i.e. I was trying to put a value larger than a short into a field with type short. I changed the myindex-\* mapping and deleted the index. It's now filling in with documents. Thank you for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2018, 6:47pm UTC](https://discuss.elastic.co/t/using-custom-target-for-geoip-filter-how-to-update-elasticsearch-template/125442/8 "2018-04-21T18:47:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
