Splunk Search

I am using geostats, I want to show multiple fields in the tooltip. Please help.

cadrija
Path Finder

My current query

source="VLS_OUTSTANDING_GEO.csv" host="dev-bnk-loaniq-" sourcetype="csv" | geostats latfield=AREA_LATITUDE longfield=AREA_LONGITUDE sum(OST_AMT_FC_CURRENT) count by OST_CDE_RQST_CCY

Giving below field in snip

cadrija_0-1638874266424.png

  • I want to show proper name instead of sum(OST_AMT_FC_CURRENT) in the tooltip.
  • I want to show the summation of the count also in the tooltip.

Like this

cadrija_1-1638874392156.png

Also is it possible not to show the latitude & longitude in the tooltip.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...