Dashboards & Visualizations

Map visualization is not available with Pivot. Is there an efficient workaround?

hsesterhenn
Path Finder

Hi,

just found out that there is no map visualization available if you use Pivot.

You can add attributes to get the geo location data from an IP address but you can't visualize it, currently.

Only workaround I see is the '| datamodel' command:

Example:

    | datamodel MyModel WebSales search | geostats latfield=WebSales.clientip_lat longfield=WebSales.clientip_long 
      sum(WebSales.price) by WebSales.product_id

This is a lot of typing... 😞

Any other idea?

Holger

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi hsesterhenn,

here is a good tutorial for some other way to get a map using data model:

http://www.function1.com/2014/09/extending-the-power-of-pivot

tstats would be another command that could be used

hope that helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi hsesterhenn,

here is a good tutorial for some other way to get a map using data model:

http://www.function1.com/2014/09/extending-the-power-of-pivot

tstats would be another command that could be used

hope that helps ...

cheers, MuS

hsesterhenn
Path Finder

Well.

The first one is JS magic. Looks cool but not exactly my point.
And no map mantioned there?????

I was talking about the Splunk Pivot function which relies on a data model.

TStats... that's another option, indeed. Pipe this output to geostats.

But it's only working if you have accelerated the data model.

Would look like this:

| tstats .... | iplocation ip_field ... | geostats ... 

Turn it into a map.

Good idea. Still manual work 🙂

Thank you,

Holger

0 Karma

MuS
SplunkTrust
SplunkTrust

uppsss too many open tabs, so I pasted the wrong URL! Updated the answer to point to the correct URL. And yes, from the pivot editor you're not able to create a map directly 😞

0 Karma

hsesterhenn
Path Finder

Sorry, missed the edited link completely...

Cool stuff and tips... worth trying!

Thank you!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...