<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can someone provide an example for Geom counts based on client IP? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282752#M85388</link>
    <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;I'm trying to generate counts/hits based on client ip and create a map visualization similar to the one found on the site for 6.3 Geographic data visualizations. Can someone help and give a simple example? &lt;/P&gt;</description>
    <pubDate>Thu, 17 Dec 2015 20:37:29 GMT</pubDate>
    <dc:creator>spammenot66</dc:creator>
    <dc:date>2015-12-17T20:37:29Z</dc:date>
    <item>
      <title>Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282752#M85388</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;I'm trying to generate counts/hits based on client ip and create a map visualization similar to the one found on the site for 6.3 Geographic data visualizations. Can someone help and give a simple example? &lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 20:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282752#M85388</guid>
      <dc:creator>spammenot66</dc:creator>
      <dc:date>2015-12-17T20:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282753#M85389</link>
      <description>&lt;P&gt;Try &lt;A href="https://splunkbase.splunk.com/app/1603/"&gt;this app&lt;/A&gt;. It contains a myriad of dashboard examples, including one that sounds like what you are trying to achieve (Under "Basic Elements" - "Maps")&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 21:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282753#M85389</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2015-12-17T21:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282754#M85390</link>
      <description>&lt;P&gt;i tried the app but i couldn't get it to work with iplocation which was why i asked the question in this forum. &lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2015 03:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282754#M85390</guid>
      <dc:creator>spammenot66</dc:creator>
      <dc:date>2015-12-20T03:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282755#M85391</link>
      <description>&lt;P&gt;Something like this should work for the SPL:&lt;/P&gt;

&lt;P&gt;assuming that the IP address you're interested in is "client_ip"&lt;/P&gt;

&lt;P&gt;...generating search...&lt;BR /&gt;
| iplocation client_ip &lt;BR /&gt;
| stats count by Country &lt;BR /&gt;
| geom geo_countries featureIdField=Country&lt;/P&gt;

&lt;P&gt;you can then set the visualization type to Choropleth&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282755#M85391</guid>
      <dc:creator>arobbins_splunk</dc:creator>
      <dc:date>2020-09-29T08:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282756#M85392</link>
      <description>&lt;P&gt;im getting the following error: "Error in 'SearchOperator:Geom': could not resolve"&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 22:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282756#M85392</guid>
      <dc:creator>spammenot66</dc:creator>
      <dc:date>2016-01-06T22:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282757#M85393</link>
      <description>&lt;P&gt;Could you post your entire search?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 22:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282757#M85393</guid>
      <dc:creator>arobbins_splunk</dc:creator>
      <dc:date>2016-01-06T22:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282758#M85394</link>
      <description>&lt;P&gt;I have similar thingy ongoing. My (workable) search is:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index="feed_inputips" source="/home/splunk/inputs/inputips.csv" | lookup geo_countries longitude as Longitude, latitude as Latitude | stats count by featureId | geom geo_countries&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Which allows me to have map with count of events (featureId) - but I am unable to have field 'SRC_ADDRESS' on the map - which IS available on inputips - can anyone provide assistance on this? How about captions?&lt;/P&gt;

&lt;P&gt;Does it matter if this run on Search (viz), not on Dashboard?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282758#M85394</guid>
      <dc:creator>strangelaw</dc:creator>
      <dc:date>2020-09-29T08:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282759#M85395</link>
      <description>&lt;P&gt;the choropleth map will only show a single aggregate split by region...&lt;/P&gt;

&lt;P&gt;given that your aggregate is count per region, that is what the choropleth will show&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 17:34:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282759#M85395</guid>
      <dc:creator>arobbins_splunk</dc:creator>
      <dc:date>2016-01-13T17:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282760#M85396</link>
      <description>&lt;P&gt;here's my query&lt;/P&gt;

&lt;P&gt;sourcetype="dcapi:realtime"     |&lt;BR /&gt;
iplocation c_ip|&lt;BR /&gt;
stats count by Country|&lt;BR /&gt;
geom geo_countries featureIdField=Country&lt;/P&gt;

&lt;P&gt;If i run it without the last line geom "geo_countries featureIdField=Country", it seems to return results fine&lt;BR /&gt;
Country count&lt;BR /&gt;
1   Spain   2&lt;BR /&gt;
2   United States   126&lt;/P&gt;

&lt;P&gt;But the minute i add the last line, i get the following error: &lt;BR /&gt;
Error in 'SearchOperator:Geom': could not resolve&lt;BR /&gt;
The search job has failed due to an error. You may be able view the job in the Job Inspector.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:23:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282760#M85396</guid>
      <dc:creator>spammenot66</dc:creator>
      <dc:date>2020-09-29T08:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282761#M85397</link>
      <description>&lt;P&gt;... I'm not sure how to help with that... but I'm going to get in front of someone who may... stay tuned...&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 18:56:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282761#M85397</guid>
      <dc:creator>arobbins_splunk</dc:creator>
      <dc:date>2016-01-15T18:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282762#M85398</link>
      <description>&lt;P&gt;Are you on Splunk 6.3? IIRC, geom wasn't implemented until 6.3. I could be wrong though...&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 19:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282762#M85398</guid>
      <dc:creator>jluo_splunk</dc:creator>
      <dc:date>2016-01-15T19:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282763#M85399</link>
      <description>&lt;P&gt;it would be nice if the choropleth could render the count onto the map. It currently only shows the count when you mouseover the region.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 20:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282763#M85399</guid>
      <dc:creator>ghendrey_splunk</dc:creator>
      <dc:date>2016-01-15T20:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282764#M85400</link>
      <description>&lt;P&gt;Usually the geom command is applied &lt;EM&gt;after&lt;/EM&gt; both  a lookup has been done against the geo lookup table and the stats. This insures that each record that you stat is accompanied by the correct name of the geo-entity from the geo lookup table. Since you are not applying a geolookup, but rather just attaching a country name via geoIp, my suspicion is that the iplocation command may be attaching country names that are not in the geo spatial lookup. My further suspicion is that a blank country name is getting attached by the geoip. Then the geom command says "cannot resolve [blank]" since it cannot find the geometry for an empty country name. One thing you can do is dig out the log (inspect job through the UI, then click to see the dispatch log). I can tell a lot from those logs. The second thing is to use an eval to make sure there are no blank country names passing through from stats. &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 20:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282764#M85400</guid>
      <dc:creator>ghendrey_splunk</dc:creator>
      <dc:date>2016-01-15T20:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282765#M85401</link>
      <description>&lt;P&gt;and post your dispatch log (inspect job)&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 20:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282765#M85401</guid>
      <dc:creator>ghendrey_splunk</dc:creator>
      <dc:date>2016-01-15T20:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282766#M85402</link>
      <description>&lt;P&gt;I tracked down "could not resolve". This actually is occurring because the "filename" key cannot be found in transforms.conf, corresponding to the geo lookup named "geo_countries". Please locate your transforms.conf file that contains a stanza named [geo_countries]. In this stanza you should see something like:&lt;BR /&gt;
[geo_countries]&lt;BR /&gt;
external_type=geo&lt;BR /&gt;
filename=XXX&lt;BR /&gt;
(where XXX  is the name of a .kmz file that resides in a folder named "lookups" under the splunk etc root).&lt;/P&gt;

&lt;P&gt;The fact that the "could not resolve" error message is occurring seems to indicate that the filename key wasn't there, which in turn makes me wonder if the [geo_countries] stanza has gotten borked somehow. &lt;/P&gt;

&lt;P&gt;Are you able to do this lookup (the geom command requirers the same conf stanza I mentioned above)? SO this is a way to check the stanza is correct (don't miss the opening pipe in this hack SPL):&lt;BR /&gt;
|stats count|eval lat =37.7792| eval lon=-122.4191|lookup geo_countries longitude as lon, latitude as lat&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282766#M85402</guid>
      <dc:creator>ghendrey_splunk</dc:creator>
      <dc:date>2020-09-29T08:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282767#M85403</link>
      <description>&lt;P&gt;again, I recommend making sure that Country is not blank in any of the geoip outputs&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 22:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282767#M85403</guid>
      <dc:creator>ghendrey_splunk</dc:creator>
      <dc:date>2016-01-21T22:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282768#M85404</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;just got the same error message. I had a typo just after geom...&lt;/P&gt;

&lt;P&gt;with your version, that would give :&lt;BR /&gt;
sourcetype="dcapi:realtime" |&lt;BR /&gt;
iplocation c_ip|&lt;BR /&gt;
stats count by Country|&lt;BR /&gt;
geom geo_country featureIdField=Country&lt;/P&gt;

&lt;P&gt;-&amp;gt;Error in 'SearchOperator:Geom': could not resolve&lt;/P&gt;

&lt;P&gt;fixed version&lt;BR /&gt;
sourcetype="dcapi:realtime" |&lt;BR /&gt;
iplocation c_ip|&lt;BR /&gt;
stats count by Country|&lt;BR /&gt;
geom geo_countries featureIdField=Country&lt;/P&gt;

&lt;P&gt;Your mileage may vary but that's probably a typo in the geom command parameters (so the geom command won't find the info needed for the map, which would lead to this error I think)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:30:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282768#M85404</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2020-09-29T08:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282769#M85405</link>
      <description>&lt;P&gt;@ghendrey and @arobbins THANK YOU very much for your time on this item. &lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 19:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282769#M85405</guid>
      <dc:creator>spammenot66</dc:creator>
      <dc:date>2016-03-02T19:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282770#M85406</link>
      <description>&lt;P&gt;you can't use geo_countries unless you declare it first before the pipe&lt;BR /&gt;
| lookup geo_countries longitude as Long, latitude as Lat&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282770#M85406</guid>
      <dc:creator>mikenagra</dc:creator>
      <dc:date>2020-09-29T09:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone provide an example for Geom counts based on client IP?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282771#M85407</link>
      <description>&lt;P&gt;you can't use geo_countries unless you declare it first before the pipe&lt;BR /&gt;
| lookup geo_countries longitude as Long, latitude as Lat&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:05:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-provide-an-example-for-Geom-counts-based-on-client/m-p/282771#M85407</guid>
      <dc:creator>mikenagra</dc:creator>
      <dc:date>2020-09-29T09:05:59Z</dc:date>
    </item>
  </channel>
</rss>

