All Apps and Add-ons

Getting Data from google geolocation api into splunk

christianmuelle
Explorer

Hey there,

I want to get some geo location information based on mac address from google API

I got the nessesary data via the following search request:
index=wifi sourcetype=netxml
| dedup wireless-network.BSSID
| table wireless-network.BSSID

When I put the data manuel to a structured json file and run the following curl command i see a json responce:
curl -d @testmac.json -H "Content-Type: application/json" -i "https://www.googleapis.com/geolocation/v1/geolocate?key="API_KEY"

How can I automate that and import the location data to visualize it. I'm a newbee.

Thanks
Christian

0 Karma

jkat54
SplunkTrust
SplunkTrust

Using the curl command in TA-Webtools (https://splunkbase.splunk.com/app/4146/) you could do the following:

index=wifi sourcetype=netxml 
| fields wireless-network.BSSID
| dedup wireless-network.BSSID 
| eval header="{\"Content-Type\": \"application/json\"}" 
| eval data="OTHERJSONDATAHERE"
| curl method=post uri="https://www.googleapis.com/geolocation/v1/geolocate" headerfield=header datafield=data debug=true

OTHERJSONDATAHERE would be whats in your file, and it needs to be escaped... you can use existng fields in eval by using concat feature.

| eval newfield="{\"aManuallyEnteredjsonField\":\"".anExistingFieldInSplunk."\"}"

would create newfield with value of {"aManuallyEnteredjsonField":"valueOfFieldExistingInSplunk"}.

0 Karma

Damien_Dallimor
Ultra Champion

If I understand correctly , in order to achieve something fully integrated , SPL search -> HTTP POST with search data -> use JSON results to feed a SPL geo visualization command to a map viz , then you are probably going to need a custom search command

This search command could take the results of your search string , perform the HTTP POST and output the results in the returned JSON.

index=wifi sourcetype=netxml | dedup wireless-network.BSSID | table wireless-network.BSSID | yourcustomcommand | geostats count

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...