Splunk Search

How do I remove Fields "values"?

HarperWCurran
Engager

I am new to splunk and still wokring out the kinks however im wondering as to why i have the iplocation of clients and ect however i want to just select one country in country field however when i select one it gives me nothing how do i get around this p1.PNGp2.PNG

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Country is not in your events, it is added by the iplocation command, you should add a where command after iplocation

<search> | iplocation clientip | where Country="India" | geostats count

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Country is not in your events, it is added by the iplocation command, you should add a where command after iplocation

<search> | iplocation clientip | where Country="India" | geostats count

HarperWCurran
Engager

Thank you!

 

0 Karma
Get Updates on the Splunk Community!

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...