Splunk Search

Google maps Errors

abovebeyond
Communicator

Hey , i ran a search string on Google Map application and i get the following errors:

search string:
source=myapp:514 | geoip clientip

Traceback (most recert call last:)
KeyError: 'clientip'

I have the field clientip in my search , and i have events.

what is wrong here?

Thanks !

Tags (2)
0 Karma
1 Solution

woodcock
Esteemed Legend

The geoip app is no longer necessary because the feature is now built into Splunk via the iplocation command so try this:

source=myapp:514 | iplocation clientip

View solution in original post

0 Karma

woodcock
Esteemed Legend

The geoip app is no longer necessary because the feature is now built into Splunk via the iplocation command so try this:

source=myapp:514 | iplocation clientip
0 Karma

abovebeyond
Communicator

thanks ill try it !

0 Karma

abovebeyond
Communicator

hey Woodcock ,

i tried with the "iplocation" command , there is no error now but i cannot see the location in the google map application...

0 Karma

woodcock
Esteemed Legend

Go to the search bar (not in a dashboard), type in your new search, click on the Visualization tab, click on the leftmost menu/control (just under the word "Events" and select Map. You no longer need Google at all.

0 Karma

abovebeyond
Communicator

Thanks , just upgrade splunk version .. didnt know it exist

0 Karma

woodcock
Esteemed Legend

The problem has to do with clientip so either you do not have the field or the field's value is not in an appropriate format. Show us an event.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...