I am on Splunk 6.4
I need to plot each and every gps lat long in a dashboard without any filtering or clustering.
My search query is -> sourcetype=geo | geostats count latfield=QueriedLatitude longfield=QueriedLongitude binspanlat=1 binspanlong=1
in other words, when i see the individual points, i should see count as 1 and not a bigger number. I have screenshots handy but cannot upload them.
i have tried these settings also with no success:
max clusters = 999
also, this happens to be a very short data set. ideally i would like to plot individual gps points for a data set of multiple magnitudes bigger. I am not sure if it is possible in Splunk.
Please help.
Thanks,
Abhi
I was able to get down to count=1 for most of the cases. Sometimes it still shows more than 1. This is how i did it.
sourcetype=geo | geostats count latfield=QueriedLatitude longfield=QueriedLongitude maxzoomlevel=18
It worked pretty closely for what i am trying to do.
I was able to get down to count=1 for most of the cases. Sometimes it still shows more than 1. This is how i did it.
sourcetype=geo | geostats count latfield=QueriedLatitude longfield=QueriedLongitude maxzoomlevel=18
It worked pretty closely for what i am trying to do.