Splunk Search

How to map every event which has a lat and long field?

jdunlea
Contributor

I have 35 events. Each one has a lat and long field. How do I map each one of them to an individual point on a map? When I use geostats, it keeps trying to throw things into "geo bins".

0 Karma

DalJeanis
Legend
0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

Make sure you reference the latfield and longfield with geostats:

sourcetype=foo
| geostats latfield=my_laitudet_field longfield=my_longitude_field count

Otherwise, Splunk will just look for fields called lat and lon. As @mtranchita mentioned, make sure you're on the visualizations tab and have selected the appropriate visualization type.

Note where it says "Cluster Map" as the visualization type:alt text

mtranchita
Communicator

I'm likely misunderstanding the question, but are you looking at the statics tab and not the visualization - or can you change the visualization type?
I think that the example from the command reference shows what you are describing.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...