Splunk Search

How to plot choropleth data on maps? I have data from multi-cloud in respective index.

sh254087
Communicator

I am trying to understand how I can plot my multi-cloud subscription/service consumption data from different geo regions, on a clustered choropleth map visualization.

I have multi-cloud subscriptions with services provisioned and consumed from different regions. 

I want to know where to start with - from reading articles and documentation, I understand I should have longitude, latitude information in my data for each of the regions that I want to plot data for(at least, if not for all). None of my CSP data in respective indexes have this information. If I have to come up with a CSV, unsure  how I'll link them to get this to working. 

 

Anyone came across similar use-case?

 

Any help would be appreciated.

Labels (4)
Tags (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you have a csv with the information, you can use lookup with a suitable key to retrieve the data relevant to each event

0 Karma

sh254087
Communicator

To keep it simpler, just trying with AWS cloud, to begin with.

Here's how my region_coordinates.csv which has the region, latitude and longitude and other fields looks like -

sh254087_0-1685360686013.jpeg

I have services and their respective cost consumption data which looks like this (on a trellis-pie visualization, just used this to convey better)- 

sh254087_1-1685360700438.jpeg

I am trying to get thispie visualization on a map something like this - (referring to 'sample dashboard example' app) - 

sh254087_2-1685360716830.jpeg

Tried geom and geostats command but did not get expected output.

 

0 Karma

sh254087
Communicator

I have the cloud consumption information indexed in real-time. I do not (or can not) have the consumption information in a csv. I want this map to showcase the cloud consumption data across different regions in real-time. I can come up with a csv having long and lat values for each cloud-regions. I'm unsure how to link these two to come up with the map visualization.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...