Hello,
I am using Splunk Enterprise 9.2.3. I have a dashboard with a built-in map visualization that shows a path using geostats. My goal is to have the hover tooltip display a human-readable timestamp, but it only shows the raw epoch time.
I have tried every standard method to fix this (search-based formatting, custom JS with a new div, CSS overrides to hide the default tooltip), but none work in my environment. The default tooltip seems to be unstoppable.
Please share the code that generates the data for the map.
eventtype=my_nav_data | eval lattitude = if(match(eventtype, "my_nav_data"), eventfield_1, null) | eval longitude = if(match(eventtype, "my_nav_data"), eventfield_2, null) | eval Altitude = if(match(eventtype, "my_nav_data"), tonumber(eventfield_3), null) | where isnotnull(lattitude) AND isnotnull(longitude) | geostats latest(_time) as epoch_time, latest(Altitude) as Altitude latfield=lattitude longfield=longitude
I tried evaluating the time after geostats as well but still the time in human readable format does not appear while hovering in map.