Splunk Enterprise

How to display map with no results?

anissabnk
Path Finder

Hello I have a question 🙂

I am working on this map.

anissabnk_0-1677169877952.png

However, when "there are no resulst returned", I want to have the empty map and not this : 

anissabnk_2-1677170000606.png

 

What can I do this ? 

<dashboard version="1.1">
<label>HPE IMC</label>
<row>
<panel>
<title>La liste des alarmes</title>
<viz type="location_tracker_app.location_tracker">
<search>
<query>index="imcfault" sourcetype="st_imcfault" severity=3 OR severity=4
| lookup switchs.csv ip AS sourceIp
| rex field=location "^(?&lt;latitude&gt;.+?), (?&lt;longitude&gt;.+?)$" | eval latitude=if(isnull(latitude),"43.123888",latitude) | eval longitude=if(isnull(longitude),"5.953356",longitude)
| table _time latitude longitude faultDesc</query>
<earliest>-15m</earliest>
<latest>now</latest>
</search>
<option name="height">800</option>
<option name="location_tracker_app.location_tracker.interval">10</option>
<option name="location_tracker_app.location_tracker.showTraces">0</option>
<option name="location_tracker_app.location_tracker.staticIcon">none</option>
<option name="location_tracker_app.location_tracker.tileSet">light_tiles</option>
<option name="refresh.display">progressbar</option>
</viz>
</panel>
</row>
</dashboard>

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Add an appendpipe command before | table.  It will create fields when no events are found.

| eval latitude=if(isnull(latitude),"43.123888",latitude) 
| eval longitude=if(isnull(longitude),"5.953356",longitude)
| appendpipe [ stats count | eval latitude="43.123888", longitude="5.953356" | where count=0 | fields - count ]
| table _time latitude longitude faultDesc

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Add an appendpipe command before | table.  It will create fields when no events are found.

| eval latitude=if(isnull(latitude),"43.123888",latitude) 
| eval longitude=if(isnull(longitude),"5.953356",longitude)
| appendpipe [ stats count | eval latitude="43.123888", longitude="5.953356" | where count=0 | fields - count ]
| table _time latitude longitude faultDesc

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

anissabnk
Path Finder

Thank youuuu for your help

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...