I'm using this Custom Cluster Map and it keeps showing the large pink bubble in South Africa and every other country with 1 event no matter what I search for. How do I fix this? https://splunkbase.splunk.com/app/3122/
eventtype=cisco-security-events dest_ip!="255.255.255.255" dest_ip!="0.0.0.0" src_ip="*" | eval isLocalIP=`local-ip-list(src_ip)` | where isLocalIP!=1 AND isnotnull(threat_reason) AND threat_reason!="-" | stats count by src_ip | iplocation src_ip | geostats latfield=lat longfield=lon count by Country
This is what the result looks like in Splunk Map for the same search:
This is what the result looks like in Custom Cluster Map for the same search (always 1 event in every blue bubble):
The custom cluster map does not support split-by (ie. the geostats ... by Country
part). It will display only the first series.
Example to plot the overall count:
... | geostats latfield=lat longfield=lon count
The custom cluster map does not support split-by (ie. the geostats ... by Country
part). It will display only the first series.
Example to plot the overall count:
... | geostats latfield=lat longfield=lon count