Splunk Search

Help generating a choropleth map using geom command

heavenisreal
Loves-to-Learn Lots

Hi There, 

I am trying to generate a choropleth map of US using the following command :
| iplocation final_ip
|search Country = "United States"
|stats count as volume by Region
|rename Region as state
|dedup state
|table state volume
|geom geo_us_states featureIdField="state" allFeatures=True

This gives a response with the fields state, volume, featureCollection, geom and but the map is still empty. Using geostats instead and then doing lookup, does give map but count aka volume is very low  . Can you help please ?

@

0 Karma

heavenisreal
Loves-to-Learn Lots

Update::: Who knew, removing the  renaming of stats count as volume would do the trick! Is that expected ? Thanks nevertheless.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

That's what I mentioned in my query.

Ha:)

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@heavenisreal -Try updating query like this:

| iplocation final_ip
|search Country = "United States"
|stats count by Region
|rename Region as state
|geom geo_us_states featureIdField="state" allFeatures=True

 

I hope this helps!!!

0 Karma

heavenisreal
Loves-to-Learn Lots

Hi @VatsalJagani 

Thanks so much for your response. I tried out removing those lines as per your suggestion and it still doesn't render the map unfortunately. Do we need geostats for the map to render or should the geom just work as it is .

 

Regards,

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@heavenisreal - geom should be enough, geostats is a different purpose.

 

To troubleshoot I would keep removing one line at a time from the search and see the statistics until I see the results in the statistics to see which line of search query has issue.

 

I hope this helps!!!

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...