thanks @niketnilay ,my query is index="test_data"| geostats latfield=Latitude longfield=Longitude count by status |sort - HIGH | head 20
here status has two value HIGH and LOW.
I haven't tried map+visualization ,just trying this .
On the map what exactly the unit for location? Is it Country or State or City or Zip? Can you try the following (I have taken City as the location identifier)
index="test_data" | eval location=City.":".Latitude.":".Longitude | chart count by location status | sort 0 - "HIGH" | head 20 | eval location=split(location,":"), City=mvindex(location,0), Latitude=mvindex(location,1), Longitude=mvindex(location,2) | fields - location | geostats latfield=Latitude longfield=Longitude sum(GET) sum(POST) by City
thanks @niketnilay for your support, actually I am new to splunk ,so I just know the basic things .On the Map I am passing Latitude and longitude only .