Splunk Search

Geostat remove "OTHER"

xisura
Communicator

Hi,

How can i remove the "OTHER" in geostats result ,i tried to add userother=f but its not working. Is there any other way to remove it.
Here's my sample search
index="test" |geostats latfield=lat longfield=lon latest(cpu) by city

Please enlighten me.

Thanks in Advance!
xisura

Tags (2)
1 Solution

xisura
Communicator

Hi Everyone,just found the answer. I added globallimit=0 in my search and it works.
globallimit=Controls the number of pies in the pie-chart. All other split-by values will be grouped under "OTHER".Setting globallimit=0 will remove all limits and all columns will be rendered

View solution in original post

carlosmd
New Member

Maybe you can try adding the fields at the end of your search:

index="test" |geostats latfield=lat longfield=lon latest(cpu) by city | fields - OTHER

As you know, it is not the best practice exclude files after doing your search, but for now you can try this solution.

I hope this will help

0 Karma

xisura
Communicator

Hi Everyone,just found the answer. I added globallimit=0 in my search and it works.
globallimit=Controls the number of pies in the pie-chart. All other split-by values will be grouped under "OTHER".Setting globallimit=0 will remove all limits and all columns will be rendered

jzapantis
Path Finder

Thanks, this solved it for me as well. Appreciation!

0 Karma

Nanuk
Explorer

Thanks! I've been looking for this fix!!

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...