Splunk Search

how to plot some count on gmaps instead of plotting count of events for given geo

kavyatim
Path Finder

Hi ,

I have a 23 faults in XXXX city with X as latitude and Y as longitude,
Now I want to plot fault count (23) on gmaps for the given lat and long.

The event count in my data for city XXXX is one, I know we can plot this 1 on gmaps for given lat/long but instead of ploting this one i want to plot 23 on gmaps.

kindly note that there are no repeated cities and lat/long in my data,each row is unique.

So I cannot proceed with and geo commands.

Can anyone thing over it and help me to plot count on gmaps for given lat/long.

dmaislin_splunk
Splunk Employee
Splunk Employee

Try using iplocation and the geostats command vs. the gmaps app.

clientip=* | iplocation clientip allfields=true | geostats count by clientip

Or to see more good stuff with it:

clientip=* | iplocation clientip allfields=true | geostats translatetoxy=false count by clientip,City,Continent,Country,Region,MetroCode,Timezone,lat,lon

Or:

clientip=* | iplocation clientip allfields=true | geostats translatetoxy=false count by clientip,City,Continent,Country,Region,MetroCode,Timezone,lat,lon | table clientip * | sort - geobin
0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...