Dashboards & Visualizations

How to create a map (geostats) with multiple fields/count by ?

Fadom1013
Explorer

Hello everyone, I'm a new in your community, thank you for the welcome 🙂

I need to display a map with several fields for each data.
I had done this for display with a single data (it works!)

 

 

 

| inputlookup  data.csv  
| search agence_rattachement="*" AND code_client_groupe=* AND nom_site=* AND id_departement=* 
| lookup villes_france.csv nom_reel AS ville_site OUTPUTNEW longitude_dgr,latitude_dgr
| lookup data-2.csv nom_site_rattachement AS  nom_site  OUTPUTNEW nombre_compresseur, numero_centrale
| geostats latfield=latitude_dgr longfield=longitude_dgr count by nom_site

 

 

 

But with a multitude of fields, it no longer works:/

I have the data (see in picture) but the map contains no points:

 

 

 

| inputlookup  data.csv  
| search agence_rattachement="*" AND code_client_groupe=* AND nom_site=* AND id_departement=* 
| lookup villes_france.csv nom_reel AS ville_site OUTPUTNEW longitude_dgr,latitude_dgr
| lookup data_2.csv nom_site_rattachement AS  nom_site  OUTPUTNEW nombre_compresseur, numero_centrale
| geostats latfield=latitude_dgr longfield=longitude_dgr translatetoxy=false count by nom_site

 

 

 

Thx you !!!! Have a good dayCapture.PNG

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

may be you can try something like below: grouped is new field show value like Country-City and calculated field is used in by clause of geostats

| makeresults | eval ip="129.10.32.10"
| iplocation ip
| eval grouped=Country+"-"+City
| geostats count by grouped

  

————————————
If this helps, give a like below.
0 Karma

Fadom1013
Explorer

Thx ! i do : 

 

 

| eval grouped = name + "_" + nb + "_" + id
| geostats latfield=latitude_dgr longfield=longitude_dgr  count by grouped

 

 



It's concatenateevery fields in one field, is good, when i am on a point of a map i have : name_number_id (he 3 fields concatenate), is good thanks !

But for the link target of the drilldown of the map i need to split it 😕 You known how ? 🙂

Because : 
<link target="_blank">/form?token=$click.name$</link> and i just nedd the name_ of the value click name (not name_nb_id)

0 Karma
Get Updates on the Splunk Community!

Splunk Developers: Go Beyond the Dashboard with These .Conf25 Sessions

  Whether you’re building custom apps, diving into SPL2, or integrating AI and machine learning into your ...

Index This | How do you write 23 only using the number 2?

July 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk ITSI & Correlated Network Visibility

  Now On Demand   Take Your Network Visibility to the Next Level In today’s complex IT environments, ...