Dashboards & Visualizations

Choropleth Map in Glass Table not working

gpugliese
Explorer

Hi all,

I wrote a SPL query to generate the table to be used as data source for a world choropleth map within my glass table on Splunk Cloud with the ITSI app.

The query is defined as follows:

index=test
| rename country as iso2
| stats count by iso2
| lookup geo_attr_countries iso2 OUTPUT country
| fields - iso2
| geom geo_countries featureIdField="country"

It runs well in the search interface (both on a Splunk Cloud instance without ITSI and with ITSI) and in a world choropleth map on a "traditional" Splunk dashboard: the country are always colored as expected.

However, when I add this query in the data configuration section of a new world choropleth map on a new glass table in the ITSI app, I get only a message of "Cannot get geoJson data.".

I supposed the glass table cannot find the data, but if I use the same query in another visualization type (e.g. table), the data are displayed as expected. Data are correct and the query works well even if I click on "open in search" near the empty widget of the map while in visualization mode.

Could you please support me in resolving this issue? I couldn't find any suggestion or example online for choropleth maps in glass tables.

Thanks,

G.P.

Labels (2)

Fraserorrr
Engager

Any Resolution, been having an identical problem 

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...