In my custom splunk app, which reads the logs generated by Barracuda web Application Firewall. I have a dashboard which has amMap flash map to show the location of clientip present in the logs. But, the map is showing incorrect location for the clientip.
The app is having two views as it is in amMap Splunk app - one is showing the count of IPs for all time and second is showing the count of IPs for the last 1 hour realtime. But the realtime map is showing the same results on the map as it is on the first map.
How can the realtime map be configured to show only the last 1 hour results on the map ?