Splunk Search

How do I display a blank map using geostats?

dzilk
Engager

When I run a search to be displayed on a map using geostats that does not include any returned data, the map doesn't display. Instead it just indicates "Search was cancelled". I would like it to display a blank map instead. Is this possible?

Tags (1)
0 Karma

paramagurukarth
Builder

Another option is there....
append an empty row to the end just with latitude and longitude value alone (before calling geostats)

to know how to append empty row please see the below link
http://answers.splunk.com/answers/41525/add-a-row-to-end-of-table.html

0 Karma

Venkat_16
Contributor

Hi paramagurukarthikeyan !<

are u using postprocess search in your Map Dashboard?

0 Karma

paramagurukarth
Builder

No I am using a custom search command and all our geo information are updated through that command( Based on IP address)
So when no geo information is available I pass dummy value for map fields.

Similarly when there are no results before geostats, pass an empty record (Event) with 0.0000 lat and 0.000 lon and all other values as "-"

0 Karma

paramagurukarth
Builder

How you are forming the latitude and longitude for your map?
If you are using any separate program to return longitude and latitude using your Client IP any other values means ... return an empty record (Event) with 0.0000 lat and 0.000 lon and all other values as "-"

0 Karma

neogeek83
New Member

I don't believe so, at least, I haven't seen a way to do it. Latest version has updated the text to be "No Results yet found," until it finishes the search and then displays "No Results found."

Would be much better to have a blank map with notice overlaid with the "No Results found."

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...