Hello Everyone,
I need your help please 🙂
I am using the Location Tracker to follow some alerts.
My spl request is :
index="imcfault" sourcetype="st_imcfault"
| lookup switchs.csv ip AS sourceIp
| rex field=location "^(?<latitude>.+?), (?<longitude>.+?)$"
| table _time latitude longitude faultDesc
The lookup switchs.csv returns the following elements :
The final result of the request is :
Thank you so much
Thank you so much @PaulPanther for your answer.
But do you know something about coloring dynamically static icon.
I want to have the static Icon in two colors :
Regarding your spl question if your fields are always empty you could use the fillnull command like
index="imcfault" sourcetype="st_imcfault"
| lookup switchs.csv ip AS sourceIp
| rex field=location "^(?<latitude>.+?), (?<longitude>.+?)$"
| table _time latitude longitude faultDesc
|fillnull field-list=label value="TOU-MAIRIE-ANX-SJV-68"
|fillnull field-list=latitude value="43.12534"
|fillnull field-list=longitude value="5.93029"
If you wanna overwrite existing fields with alternating values you could use eval command with case (Comparison and Conditional functions - Splunk Documentation)
Regarding the visualization question do you use following add-on for it Maps+ for Splunk | Splunkbase?
Thank you so much @PaulPanther for your answer.
But do you know something about coloring dynamically static icon.
I want to have the static Icon in two colors :
Thank you so much @PaulPanther for your answer.
But do you know something about coloring dynamically static icon.
I want to have the static Icon in two colors :
Regarding the visualization question do you use the add-on Maps+ for Splunk | Splunkbase for it?
Ok thank you, I will see