Splunk Search

Using multiple geospatial lookups

sigpro1911
New Member

Thanks in advance for any help.

I currently am using a geospatial file to show devices inside or outside of a geofence.

Here is a small snippet of the search

           | lookup geo_Example1 latitude longitude
           | fillnull featureId value="outsideGeoFence"
           | where LIKE(featureId, "outsideGeoFence") 
           | fillnull value="unknown" user

I can use any single geo spatial file such as Example1 Example2 Example3 that I have loaded referencing the latitude and longitude and it works as expected.

I would ideally like to add more than one geospatial lookup to the search instead of creating multiple reports or dashboards for each specific location

I have tried simply adding another lookup to the string in different ways but it is not working once I add more thane one Geospatial reference.

Tags (2)
0 Karma

DalJeanis
Legend

Basically, you just have to rename them in between lookups to get them out of the way.

        | lookup geo_Example1 latitude longitude
        | rename featureId as featureId1, user as user1
        | lookup geo_Example2 latitude longitude
        | rename featureId as featureId2, user as user2
        | lookup geo_Example3 latitude longitude
        | rename featureId as featureId3, user as user3
        | eval featureId=coalesce(featureId1,featureId2,featureId3, "outsideAllGeoFences")
        | eval user=coalesce(user1, user2,user3,"unknown")
0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...