Splunk Search

How to plot data on the Splunk Map from lookup data using Country Name, Country Code, City Name but not IP?

DanielFordWA
Contributor

I have a system that requires authentication so each user has a unique identifier.

I have a lookup to enrich users that can return the "Location Country" or "Location Region" or ISO country codes.

I would like to plot data against these users actions on the Splunk map. I do not have access to the users IP address.

I've looked around for a while but have no idea how to do this, can anyone point me in the right direction?

Thanks,

Dan

Edit: for clarification... is there a way I can take the ISO country codes, or city names and look them up to produce a longitude and latitude, then use that in the maps?

It would seem like a trick has been missed if you cant convert ISO country codes this way.

Tags (3)
1 Solution

DanielFordWA
Contributor

Ok I found this.

https://opendata.socrata.com/dataset/Country-List-ISO-3166-Codes-Latitude-Longitude/mnkm-8ram

I hoped Splunk could do this without adding another lookup.

Cheers,

Dan

View solution in original post

DanielFordWA
Contributor

Ok I found this.

https://opendata.socrata.com/dataset/Country-List-ISO-3166-Codes-Latitude-Longitude/mnkm-8ram

I hoped Splunk could do this without adding another lookup.

Cheers,

Dan

marina_rovira
Contributor

Hello! How did you resolve this? I'm trying to visualize the data per cities in a map and I'm not achieving it 😞

Thank you!

0 Karma

strive
Influencer
0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...