I've successfully downloaded the app and when I try my search, I get some matching events, but nothing appears on the map... I know this is incorrect, because I should be getting a number of countries in my results
here's my search:
sourcetype="t_test" | lookup geoip clientip as ip_address | top limit=10000 client_country
Anyone know what might be the problem? I want to have the map display for my dashboard
Using ... | top limit=1000 client_country
you're emitting the client_country field. In order to get results on the map you need to emit the _geo field ( see app documentation for more details http://splunk-base.splunk.com/apps/22365/google-maps ).
sourcetype="t_test" | geoip clientip
for example emits this _geo field (among others).