Hey all,
So, I need a geo map: locations (IP address) using ip address and when I try to use
"........| iplocation IPAddress"
then no Country or City fields appear.
The data is getting extracted in a .CSV using a python script and .CSV file has only above mentioned fields.
So my question is:
Do I need to have country and city fields also in .csv or we can obtain locations just using ipaddress?
thanks
Hello @splunkuseradmin,
This query should work. If not please check field name and ip-address values once.
| iplocation IPAddress
| geostats latfield=lat longfield=lon count
Hope this helps!!!
@splunkuseradmin,
Try this and select cluster map as visualization
your current search | iplocation IPAddress|geostats latfield=lat longfield=lon count by IPAddress
Hello @splunkuseradmin,
This query should work. If not please check field name and ip-address values once.
| iplocation IPAddress
| geostats latfield=lat longfield=lon count
Hope this helps!!!
Oops! my bad I was trying the same, what you guys suggesting but the mistake was in the field Ipaddress name correct field name is is "IP Address".
anyways you gave me the right answer thogh i check this one.