<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AmMap and realtime? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/AmMap-and-realtime/m-p/14290#M1489</link>
    <description>&lt;P&gt;I've been able to get AmMap to work with scheduled searches. Is there a way to get it to work in realtime? I thought I saw this demonstrated at the splunk live event in Washington DC last week. I've searched without much luck for an answer. The default AmMap app comes with a "Real Time AMMAP view" does anyone know how I put the data into this view. It doesn't appear to be the same file as the scheduled searches/ regular AmMap.&lt;/P&gt;

&lt;P&gt;Thanks,
Jason&lt;/P&gt;</description>
    <pubDate>Wed, 26 May 2010 21:27:15 GMT</pubDate>
    <dc:creator>jjernigan</dc:creator>
    <dc:date>2010-05-26T21:27:15Z</dc:date>
    <item>
      <title>AmMap and realtime?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/AmMap-and-realtime/m-p/14290#M1489</link>
      <description>&lt;P&gt;I've been able to get AmMap to work with scheduled searches. Is there a way to get it to work in realtime? I thought I saw this demonstrated at the splunk live event in Washington DC last week. I've searched without much luck for an answer. The default AmMap app comes with a "Real Time AMMAP view" does anyone know how I put the data into this view. It doesn't appear to be the same file as the scheduled searches/ regular AmMap.&lt;/P&gt;

&lt;P&gt;Thanks,
Jason&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2010 21:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/AmMap-and-realtime/m-p/14290#M1489</guid>
      <dc:creator>jjernigan</dc:creator>
      <dc:date>2010-05-26T21:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: AmMap and realtime?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/AmMap-and-realtime/m-p/14291#M1490</link>
      <description>&lt;P&gt;Hi Jason,
That view should be working, if not, you may want to try an updated build on splunkbase. The setup for this is simple though. Notice the HTML refers to a rt_settings file, you'll need to include that in the HTML you will be pulling in via a ServerSideInclude.&lt;/P&gt;

&lt;P&gt;The view XML looks like this:&lt;/P&gt;

&lt;P&gt;
    src_ip=* src_ip!=10.* src_ip!=192.* src_ip!=0.0.* | stats count by src_ip | eval count_label="Event" | eval iterator="src_ip" | eval iterator_label="IP" | eval movie_color="#FF0000" | eval output_file="rt_threat_data.xml" | eval app="amMap" | lookup geoip clientip as src_ip | mapit
        rt
        rt
&lt;/P&gt;

&lt;P&gt;
    rt_map.html
  &lt;/P&gt;

&lt;P&gt;&lt;/P&gt;

&lt;P&gt;Notice the JobProgressIndicator jammed in there. This is so the real time search actually gets kicked off. Let us know if you need a hand getting this working. &lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2010 11:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/AmMap-and-realtime/m-p/14291#M1490</guid>
      <dc:creator>Will_Hayes</dc:creator>
      <dc:date>2010-05-27T11:17:51Z</dc:date>
    </item>
  </channel>
</rss>

