I have field in my log that call “MobileNumber” that need to show count of MobileNumber by location on map.
if area code belong to Berlin 0151, 0157 or 0173. show total count of area code that belong Berlin on map.
if area code belong to Wolfsburg 0361 show total count of area code that belong Wolfsburg on map
FYI: Latitude, Longitude not exist in log file.
This is not the full solution, but you could eval the longitude and latitude for each result.
Or use a lookup with all cities lon and lats.
| eval City = "Berlin" |eval lat="52.520008" | eval lon="13.404954"
| geostats latfield=lat longfield=lon count
I'd say create a lookup with area codes and their respective longitudes and latitudes.
Splunk can do magic, but you need to feed it some ingredients to do magic with.
I found this as a possible source: