- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
seetharamanss
Explorer
08-29-2016
10:58 AM
Hi,
I'm trying to do a simple MAP visualization with the search below, but it is throwing me error no match found. Is there any thing I'm missing out?
host = "hostname" sourcetype = "sourcetypelog" MarketName =SINGAPORE | geostats latfield=1.3667 longfield=103.8 count by MarketName
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sundareshr
Legend
08-29-2016
11:07 AM
Try this
... | eval lat="1.3667" | eval lon="103.8"| geostats latfield=lat longfield=lon count by MarketName
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
s2_splunk

Splunk Employee
08-29-2016
11:55 AM
latfield/longfield are meant to be the field names for latitude and longitude, not the field values.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sundareshr
Legend
08-29-2016
11:07 AM
Try this
... | eval lat="1.3667" | eval lon="103.8"| geostats latfield=lat longfield=lon count by MarketName
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
seetharamanss
Explorer
08-29-2016
02:16 PM
Thank you . It worked
