Splunk Search

Map on splunk 6


Is there a way to use the google map app or something similar in splunk 6?
I have syslogs containing latitude and longitude which I would like to display on a map.

Tags (3)


If you want to display a map.. you can use simple xml's map element....
But if you want to display a map inside advanced xml.. there is no direct way to achieve it...
A Work Around is there...
You can create a map dashboard using simple xml and load its url inside your advanced xml using iframeInclue module
and attach a css to your simple xml map module with below classes
body, td {
min-width: 0 !important;
font-family: Arial,Helvetica,sans-serif !important;

Refernce for IframeInclude - http://docs.splunk.com/Documentation/Splunk/6.2.0/AdvancedDev/UseHTML

0 Karma


Can I change color of the base Splunk 6 default map?
If possible, how can i change this?

0 Karma


Change the color means.. Do you want to change the tiles..
If you want to change the tile please refer...

 <option name="mapping.tileLayer.url">http://{s}.tile.openstreetmap.org/{z}/{x}/{y}.png</option>
   <option name="mapping.tileLayer.subdomains">[a,b,c]</option>
   <option name="mapping.tileLayer.maxZoom">18</option>



if you want to change the plot colors..
please refer mapping.seriesColors in the same URL


Yes I want to change the tiles color. But not change..
Please show me example

0 Karma


Add these properties to your map tag

   <option name="mapping.tileLayer.url">http://{s}.tile.openstreetmap.org/{z}/{x}/{y}.png</option>
   <option name="mapping.tileLayer.subdomains">[a,b,c]</option>
   <option name="mapping.tileLayer.maxZoom">18</option>
   <option name="mapping.tileLayer.attribution">
     Map data (c) 2012 OpenStreetMap contributors, CC-BY-SA.

You can get different layers URl from this site

0 Karma

Path Finder


I've created a new app that provides a couple more map visualizations options then the built in splunk ones.
It can do marker maps and cluster maps (similar to the ones existing in Splunk).

But it can also do heat maps and "shape" maps.

See: https://apps.splunk.com/app/1887/

You'll find more screenshots here: https://github.com/pvanisacker/heremaps/tree/master/appserver/static

The app is still in early state of development so if you spot any issues, let me know. And the app only supports 6.1 for now.

Splunk Employee
Splunk Employee

Here is an example of mapping Blue Coat Dest IP Location to a Splunk 6 native map using the Splunk CIM Web data model.

        <title>Countries Count by GEOIP</title>
| pivot Web Web count(Web) AS "Count of Proxy Events"  SPLITROW dest AS dest FILTER Last_Logged_On_User is $userid$   
SORT 100 dest ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 | iplocation dest | table * | geostats count by dest 
        <option name="wrap">true</option>
        <option name="rowNumbers">false</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">all</option>
        <option name="count">10</option>
        <option name="mapping.data.maxClusters">100</option>
        <option name="mapping.map.center">(0,0)</option>
        <option name="mapping.map.zoom">2</option>
        <option name="mapping.markerLayer.markerMaxSize">50</option>
        <option name="mapping.markerLayer.markerMinSize">10</option>
        <option name="mapping.markerLayer.markerOpacity">0.8</option>
        <option name="mapping.tileLayer.maxZoom">7</option>
        <option name="mapping.tileLayer.minZoom">0</option>
0 Karma


This looks promising. Thank you!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...