Splunk Search

Why is my cluster map working fine in verbose mode but not in fast mode?

ajitshukla
Explorer
query:- index="test"|table FIELD1,FIELD2,Latitude,Longitude,Timestamp| geostats latfield=Latitude longfield=Longitude count by FIELDD1

Result For Verbose Mode
alt text

result for fastmode:

NO RESULT FOUND

0 Karma
1 Solution

chrisyounger
SplunkTrust
SplunkTrust

Hi @ajitshukla

try this: index="test"|fields FIELD1 FIELD2 Latitude Longitude Timestamp| geostats latfield=Latitude longfield=Longitude count by FIELD1

Hope this helps

View solution in original post

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @ajitshukla

try this: index="test"|fields FIELD1 FIELD2 Latitude Longitude Timestamp| geostats latfield=Latitude longfield=Longitude count by FIELD1

Hope this helps

0 Karma

ajitshukla
Explorer

thanks its working fine

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Awesome, glad to hear it!

|fields is typically better and faster to use than |table

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...