Dashboards & Visualizations

GEOSTATS Rename value lat and lon in piechart

4nton10
Loves-to-Learn Lots

Hi everyone.

 

I am generating a cluster map which to make a count by log_subtype and in the map itself shows me the county and the latitude and longitude data.

The question here is whether I can replace the latitude and longitude data with the name of the country.

4nton10_0-1704829496478.png

 

I have the query as follows:

 

| iplocation client_ip
| geostats count by log_subtype
Labels (1)
Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can't replace the lat/long, but you can add country to the log_subtype, i.e.

| iplocation client_ip
| eval type=log_subtype." (".Country.")"
| geostats count by type
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @4nton10

Thru geostats, it may be a long route, maybe please try "choropleth" maps

https://docs.splunk.com/Documentation/Splunk/9.1.2/Viz/ChoroplethGenerate

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...