Splunk Search

How do I display a blank map using geostats?

dzilk
Engager

When I run a search to be displayed on a map using geostats that does not include any returned data, the map doesn't display. Instead it just indicates "Search was cancelled". I would like it to display a blank map instead. Is this possible?

Tags (1)
0 Karma

paramagurukarth
Builder

Another option is there....
append an empty row to the end just with latitude and longitude value alone (before calling geostats)

to know how to append empty row please see the below link
http://answers.splunk.com/answers/41525/add-a-row-to-end-of-table.html

0 Karma

Venkat_16
Contributor

Hi paramagurukarthikeyan !<

are u using postprocess search in your Map Dashboard?

0 Karma

paramagurukarth
Builder

No I am using a custom search command and all our geo information are updated through that command( Based on IP address)
So when no geo information is available I pass dummy value for map fields.

Similarly when there are no results before geostats, pass an empty record (Event) with 0.0000 lat and 0.000 lon and all other values as "-"

0 Karma

paramagurukarth
Builder

How you are forming the latitude and longitude for your map?
If you are using any separate program to return longitude and latitude using your Client IP any other values means ... return an empty record (Event) with 0.0000 lat and 0.000 lon and all other values as "-"

0 Karma

neogeek83
New Member

I don't believe so, at least, I haven't seen a way to do it. Latest version has updated the text to be "No Results yet found," until it finishes the search and then displays "No Results found."

Would be much better to have a blank map with notice overlaid with the "No Results found."

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...