I am working on a query where I have a data in below format:
How can I show these hub Ids on the map with their status (if they are open or closed)?
I am using Splunk Enterprise edition v 7.2.6
Hi, folks. how about this?
| makeresults
| eval _raw="Hub_Id,Status,Latitude,Longitude
111,Open,52.6536,2.1815
222,Close,51.27171,3.06422
333,Open,12.6536,2.1815
444,Close,22.6536,2.1815"
| multikv forceheader=1
| rename Latitude as latitude, Longitude as longitude
| eval description = "\"".Hub_Id.": ".Status."\""
| table latitude,longitude,description
Viz >> [Map+](https://splunkbase.splunk.com/app/3124/)
![Map+ Visuallization][1]
Hi, folks. how about this?
| makeresults
| eval _raw="Hub_Id,Status,Latitude,Longitude
111,Open,52.6536,2.1815
222,Close,51.27171,3.06422
333,Open,12.6536,2.1815
444,Close,22.6536,2.1815"
| multikv forceheader=1
| rename Latitude as latitude, Longitude as longitude
| eval description = "\"".Hub_Id.": ".Status."\""
| table latitude,longitude,description
Viz >> [Map+](https://splunkbase.splunk.com/app/3124/)
![Map+ Visuallization][1]
This is good, but won't work for since I do not have "Maps+ for Splunk" as a visualization
Well, got the Maps+ Installed and all sorted. Thank you !
https://splunkbase.splunk.com/app/3124/
will you download and try?
@pahujadeep
sorry, i delete all comment.
https://imgur.com/6cVuR1G
my sample maps+
no worries !! but thanks this is really useful. Will try to install maps+ , hope this will solve my problem
Many thanks again ! 🙂