# Visualize GEO location

**URL:** <https://discuss.elastic.co/t/visualize-geo-location/98937>\
**Category:** Logstash\
**Created:** [August 31, 2017, 5:32am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937 "2017-08-31T05:32:42Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 5:32am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/1 "2017-08-31T05:32:42Z")

</div>

I am trying to visualize GEO locations using ELK but getting an exception while selecting the bucket GEO coordinates "No Compatible Fields: The "\_\_\_\_" index pattern does not contain any of the following field types: geo\_point".

Please kindly help me to resolve this issue and get working. Thank in advance.

# logstash conf:

input {  
stdin { }  
}

filter {  
grok {  
match =\> {  
"message" =\> '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'   
}  
}

date {  
match =\> ["timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]  
locale =\> en  
}

geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/data/GeoLite2-City.mmdb"   
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}

```
mutate {
	 convert => ["[geoip][coordinates]", "float"]
}	

```

useragent {  
source =\> "agent"  
target =\> "useragent"  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "apache\_elk\_example"  
template =\> "/data/apache\_template.json"  
template\_name =\> "apache\_elk\_example"  
template\_overwrite =\> true  
}

# template json:

{  
"template": "apache\_elk\_example",  
"settings": {  
"index.refresh\_interval": "5s"  
},  
"mappings": {  
"_default_": {  
"dynamic\_templates": [  
{  
"message\_field": {  
"mapping": {  
"index": "analyzed",  
"omit\_norms": true,  
"type": "string"  
},  
"match\_mapping\_type": "string",  
"match": "message"  
}  
},  
{  
"string\_fields": {  
"mapping": {  
"index": "analyzed",  
"omit\_norms": true,  
"type": "string",  
"fields": {  
"raw": {  
"index": "not\_analyzed",  
"ignore\_above": 256,  
"type": "string"  
}  
}  
},  
"match\_mapping\_type": "string",  
"match": "\*"  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date"  
},   
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "float" },  
"longitude" : { "type" : "float" }  
}  
},  
"@version": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"location" : { "type": "geo\_point" }  
},  
"\_all": {  
"enabled": true  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 5:45am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/2 "2017-08-31T05:45:02Z")

</div>

What are the actual mappings of the index? What does an example event look like (copy/paste from Kibana's JSON tab)?

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 6:19am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/3 "2017-08-31T06:19:18Z")

</div>

Hi Magnus,

Please find below the mapping.

{  
"\_index": "apache\_elk\_example",  
"\_type": "logs",  
"\_id": "AV4yrDrm8y3sHjU\_dCQb",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"request": "/files/grok/?C=N;O=A",  
"geoip": {  
"timezone": "Europe/Amsterdam",  
"ip": "5.10.83.53",  
"latitude": 52.35,  
"continent\_code": "EU",  
"city\_name": "Amsterdam",  
"country\_name": "Netherlands",  
"country\_code2": "NL",  
"country\_code3": "NL",  
"region\_name": "North Holland",  
"location": {  
"lon": 4.9167,  
"lat": 52.35  
},  
"postal\_code": "1091",  
"region\_code": "NH",  
"longitude": 4.9167  
},  
"auth": "-",  
"ident": "-",  
"verb": "GET",  
"message": "5.10.83.53 - - [20/May/2015:21:05:59 +0000] "GET /files/grok/?C=N;O=A HTTP/1.1" 200 3894 "-" "Mozilla/5.0 (compatible; AhrefsBot/5.0; +http://ahrefs.com/robot/)"",  
"@timestamp": "2015-05-20T21:05:59.000Z",  
"response": "200",  
"bytes": "3894",  
"clientip": "5.10.83.53",  
"@version": "1",  
"host": "JOHN2403",  
"httpversion": "1.1",  
"timestamp": "20/May/2015:21:05:59 +0000"  
},  
"fields": {  
"@timestamp": [  
1432155959000  
]  
},  
"sort": [  
1432155959000  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 7:49am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/4 "2017-08-31T07:49:13Z")

</div>

That's an example doc, not the mappings of the index. Use the get mapping API for that. The example document looks fine, but if the index template hasn't been applied things won't work anyway.

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 7:50am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/5 "2017-08-31T07:50:55Z")

</div>

{  
"apache\_elk\_example":{  
"mappings":{  
"logs":{  
"properties":{  
"@timestamp":{  
"type":"date"  
},  
"clientip":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"geoip":{  
"properties":{  
"city\_name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"continent\_code":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"coordinates":{  
"type":"float"  
},  
"country\_code2":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"country\_code3":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"country\_name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"dma\_code":{  
"type":"long"  
},  
"ip":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"latitude":{  
"type":"float"  
},  
"location":{  
"properties":{  
"lat":{  
"type":"float"  
},  
"lon":{  
"type":"float"  
}  
}  
},  
"longitude":{  
"type":"float"  
},  
"postal\_code":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"region\_code":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"region\_name":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"timezone":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
}  
}  
},  
"latitude":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"location":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"longitude":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
},  
"message":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
}  
"verb":{  
"type":"text",  
"fields":{  
"keyword":{  
"type":"keyword",  
"ignore\_above":256  
}  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 7:53am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/6 "2017-08-31T07:53:49Z")

</div>

Next time please format this kind of stuff as preformatted text so it has a chance of becoming readable.

The `[geoip][location]` field isn't mapped as geo\_point. Perhaps you created/updated the index template after that field had already been mapped. Reindex your data or just drop/recreate the index if you only have test data in it.

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 8:02am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/7 "2017-08-31T08:02:47Z")

</div>

Thanks for your valuable inputs. I have dropped and recreated new index (apache\_elk\_example to apache\_elk) but getting the same error.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 8:54am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/8 "2017-08-31T08:54:50Z")

</div>

So the mappings for the index haven't changed? Have you verified that the index template is actually present in ES? I would, without using Logstash,

- drop the current apache\_elk\_example index,
- doublecheck the presence and contents of the apache\_elk\_example index template,
- create a new apache\_elk\_example index and check its mappings.

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 9:23am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/9 "2017-08-31T09:23:40Z")

</div>

As per your inputs I have tried as below but the [geoip][location] field isn’t mapped as geo\_point.

- Dropped the index and verified using [http://localhost:9200/\_cat/indices/](http://localhost:9200/_cat/indices/) (Index apache\_elk\_example was removed). Recreated new index as "apache\_elk"
- Checked the contents of the template and template name is now updated as "template": "apache\_elk".

"location": {  
"properties": {  
"lat": {  
"type": "float"  
},  
"lon": {  
"type": "float"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 9:38am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/10 "2017-08-31T09:38:06Z")

</div>

Did you update the template before or after you created the index?

You know that the `template` field in the index template supports wildcards, right?

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 9:53am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/11 "2017-08-31T09:53:22Z")

</div>

Yes Magnus, I have updated the template as well 😥

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 9:55am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/12 "2017-08-31T09:55:50Z")

</div>

"Yes" isn't a valid answer to the question "did you update the template before or after you created the index".

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 10:02am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/13 "2017-08-31T10:02:49Z")

</div>

Its working Magnus. I got the answer from your reply.

Thanks a lot 😂

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 10:22am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/14 "2017-08-31T10:22:24Z")

</div>

I am getting another exception while importing the kibana dashboard json. Could you please suggest me a solution?

"Importing Unique Visitors (Unique-Visitors) failed: Could not locate that index-pattern-field (id: geoip.ip.raw)"

---

<div class="post-metadata">

**Author:** ![immandotnet](https://avatars.discourse-cdn.com/v4/letter/i/91b2a8/32.png) [@immandotnet](https://discuss.elastic.co/u/immandotnet)\
**Post date:** [August 31, 2017, 10:33am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/15 "2017-08-31T10:33:15Z")

</div>

Now its working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2017, 10:33am UTC](https://discuss.elastic.co/t/visualize-geo-location/98937/16 "2017-09-28T10:33:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
