Splunk Search

Geostat remove "OTHER"

xisura
Communicator

Hi,

How can i remove the "OTHER" in geostats result ,i tried to add userother=f but its not working. Is there any other way to remove it.
Here's my sample search
index="test" |geostats latfield=lat longfield=lon latest(cpu) by city

Please enlighten me.

Thanks in Advance!
xisura

Tags (2)
1 Solution

xisura
Communicator

Hi Everyone,just found the answer. I added globallimit=0 in my search and it works.
globallimit=Controls the number of pies in the pie-chart. All other split-by values will be grouped under "OTHER".Setting globallimit=0 will remove all limits and all columns will be rendered

View solution in original post

carlosmd
New Member

Maybe you can try adding the fields at the end of your search:

index="test" |geostats latfield=lat longfield=lon latest(cpu) by city | fields - OTHER

As you know, it is not the best practice exclude files after doing your search, but for now you can try this solution.

I hope this will help

0 Karma

xisura
Communicator

Hi Everyone,just found the answer. I added globallimit=0 in my search and it works.
globallimit=Controls the number of pies in the pie-chart. All other split-by values will be grouped under "OTHER".Setting globallimit=0 will remove all limits and all columns will be rendered

jzapantis
Path Finder

Thanks, this solved it for me as well. Appreciation!

0 Karma

Nanuk
Explorer

Thanks! I've been looking for this fix!!

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...