Dashboards & Visualizations

Splunk Maps plotting using physical address (not IP Address)

RyanDonnelly22
Explorer

I am trying to create a map visualization from a list of data that has the the physical address of the event in a filed named 'location' 

| inputlookup data.csv | table location |

Example data

  • Earth
  • Wytheville, VA
  • Boston, MA
  • 1 Main St, Waltham, Massachusetts
  • Mexico City, Mexico
  • Wellington St, Ottawa, ON K1A 0A9, Canada

I want to talk these physical addresses and add them to the Map Visualization in Splunk, but am not seeing how to add the data to the chart. 

 

Labels (2)
0 Karma

Funderburg78
Path Finder

you need to identify the LAT and LONG.  Ordinarily splunk will perform a whois call and determine the lat/long of the domain the ip is associated with if connected to the internet.  If you want to do this differently, I think you need to apply lat/long yourself.  I do not believe there is an automatic lookup.  there are a couple ways you can accomplish this.  You can build your own lookup table to convert addresses to a lat/long or you can just input the lat/long directly into the data if it is something like a spreadsheet.

 

For reading about chloropleth maps:

https://www.splunk.com/en_us/blog/tips-and-tricks/mapping-with-splunk.html

 

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...