All Apps and Add-ons

Getting Data from google geolocation api into splunk


Hey there,

I want to get some geo location information based on mac address from google API

I got the nessesary data via the following search request:
index=wifi sourcetype=netxml
| dedup wireless-network.BSSID
| table wireless-network.BSSID

When I put the data manuel to a structured json file and run the following curl command i see a json responce:
curl -d @testmac.json -H "Content-Type: application/json" -i ""API_KEY"

How can I automate that and import the location data to visualize it. I'm a newbee.


0 Karma


Using the curl command in TA-Webtools ( you could do the following:

index=wifi sourcetype=netxml 
| fields wireless-network.BSSID
| dedup wireless-network.BSSID 
| eval header="{\"Content-Type\": \"application/json\"}" 
| curl method=post uri="" headerfield=header datafield=data debug=true

OTHERJSONDATAHERE would be whats in your file, and it needs to be escaped... you can use existng fields in eval by using concat feature.

| eval newfield="{\"aManuallyEnteredjsonField\":\"".anExistingFieldInSplunk."\"}"

would create newfield with value of {"aManuallyEnteredjsonField":"valueOfFieldExistingInSplunk"}.

0 Karma

Ultra Champion

If I understand correctly , in order to achieve something fully integrated , SPL search -> HTTP POST with search data -> use JSON results to feed a SPL geo visualization command to a map viz , then you are probably going to need a custom search command

This search command could take the results of your search string , perform the HTTP POST and output the results in the returned JSON.

index=wifi sourcetype=netxml | dedup wireless-network.BSSID | table wireless-network.BSSID | yourcustomcommand | geostats count

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...