Splunk Search

Geostat remove "OTHER"

xisura
Communicator

Hi,

How can i remove the "OTHER" in geostats result ,i tried to add userother=f but its not working. Is there any other way to remove it.
Here's my sample search
index="test" |geostats latfield=lat longfield=lon latest(cpu) by city

Please enlighten me.

Thanks in Advance!
xisura

Tags (2)
1 Solution

xisura
Communicator

Hi Everyone,just found the answer. I added globallimit=0 in my search and it works.
globallimit=Controls the number of pies in the pie-chart. All other split-by values will be grouped under "OTHER".Setting globallimit=0 will remove all limits and all columns will be rendered

View solution in original post

carlosmd
New Member

Maybe you can try adding the fields at the end of your search:

index="test" |geostats latfield=lat longfield=lon latest(cpu) by city | fields - OTHER

As you know, it is not the best practice exclude files after doing your search, but for now you can try this solution.

I hope this will help

0 Karma

xisura
Communicator

Hi Everyone,just found the answer. I added globallimit=0 in my search and it works.
globallimit=Controls the number of pies in the pie-chart. All other split-by values will be grouped under "OTHER".Setting globallimit=0 will remove all limits and all columns will be rendered

jzapantis
Path Finder

Thanks, this solved it for me as well. Appreciation!

0 Karma

Nanuk
Explorer

Thanks! I've been looking for this fix!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...