Splunk Search

Can I use geostats without latitude and longitude fields in my log

iyersudh
Explorer

The application log I am working with has ISO 3166 country code but no latitude and longitude details.

With that I am able to use a choropleth using the geom command easily using featureIdFIeld=countryname but I want to also visualize a cluster map also by country. Is there a way I can use geostats on this log without having latitude and longitude? 

Tags (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @iyersudh geostats command uses lat and long to plot over the map (The events are clustered based on latitude and longitude fields in the events).
without lat/long, it is impossible to work on the maps(or, maybe some apps/addons need to be designed for this task). 

everybody prefers the simple and easy route... ie, uploading/adding the lat/long lookup file to a splunk environment.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

to4kawa
Ultra Champion

There is not the way  to geostats command without lat & long.

https://gist.github.com/sindresorhus/1341699
you should make the lookup like above.

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...