hi
I use a basic search in order to count the number of incidents by town
index=toto sourcetype=tutu
| stats dc(id) by siteNow I would be able o display this results on a map in order to have a bubble with the number of incidents for each site
So I have created a lookup (gps.csv) like this
site,Longitude,Latitude,
AGDE,3.4711992,43.3154
NANTES,-1.58295,47.235197
TOULOUSE,1.3798,43.6091
So what I have to for doing a cross between my search and my lookup in order to have a bubble count on my map vizualisation?
thanks
I see the events only in the "events" tab
But i cant see the events related to my lookup
Yet, if i just execute, I can see the events
| lookup gps.csv site
Does this help?
| lookup gps.csv site
I have no isssue but nothing is dispalyed on the map.....
I have done this
index=toto sourcetype=tutu
| lookup gps.csv site
| geostats dc(id) latfield=Latitude longfield=Longitude by site
what is wrong please??
What are your resilts after just lookup?
What are your results after geostats?
After lookup I have results (73 events)
But geostats when I a m going in visualisation tab, there is no map displayed
You have no results (Statistics (0)!) - what does the rest of your search actually look like?
here is the search
index=tutu sourcetype=toto
| search site=*agde* OR site=*nantes* OR site=*toulouse*
| lookup gps4.csv site
| geostats count(signaler_id) latfield=latitude longfield=longitude by site
If your examples are anything to go by your site is in lowercase whereas your lookup in is uppercase - either convert the site from the search to uppercase or make sure you have set up a case-insensitive lookup definition
I have added an upper command but it changes anything
index=toto sourcetype=tutu
| search site=*agde* OR site=*nantes* OR site=*toulouse*
| eval site=upper(site)
| lookup gps4.csv site
| geostats count(signaler_id) latfield=latitude longfield=longitude by site
The issue is probably with your events - if you don't share them, anonymised of course, it is very difficult to help you.
Yes, but it's difficult to share events dont displayed....
The only thing I can say is that the site field in "gps.csv" is in Upper case
Previously, you said you had 73 events (prior to lookup?) - can you share some of them?
I understand that you get some results. But what do they look like?
Hi
I have explained it in the previous message
I cant share nothing interesting....