Splunk Search
Highlighted

geostat question for multiple indexes

Contributor

i have a unique type of column in 4 different indexes , but they all have similar latitude and longitude.

can i show all these 4 column values ( or percentage ) on a single geostat command...
in other words can a single geostat show 4 different values from 4 different indexes.

ex of 2 indexes . i have type=a and its percentage in index1
i have type=b and its percentage in index2

now when i run the geostat command with lat/lon , i wish to see that location on the map, showing both these 2 types and their respective percentages.

is it possible with splunk /geostat ?

0 Karma
Highlighted

Re: geostat question for multiple indexes

SplunkTrust
SplunkTrust

hey you can try something like this

 index=index1 OR index=index2 OR index=index3 OR index=index4 | geostats latfield=lat longfield=lon values(percentage)  by type

let me know if this helps you!

View solution in original post

0 Karma
Highlighted

Re: geostat question for multiple indexes

SplunkTrust
SplunkTrust

have you tried this?

0 Karma
Highlighted

Re: geostat question for multiple indexes

Contributor

Yes, i dumped all the different indexes into a single index with similar columns and made it easier for me. thanks..
john.

0 Karma