I am new to splunk and still wokring out the kinks however im wondering as to why i have the iplocation of clients and ect however i want to just select one country in country field however when i select one it gives me nothing how do i get around this
Country is not in your events, it is added by the iplocation command, you should add a where command after iplocation
<search> | iplocation clientip | where Country="India" | geostats count
Country is not in your events, it is added by the iplocation command, you should add a where command after iplocation
<search> | iplocation clientip | where Country="India" | geostats count
Thank you!