Splunk Search

how to plot some count on gmaps instead of plotting count of events for given geo

kavyatim
Path Finder

Hi ,

I have a 23 faults in XXXX city with X as latitude and Y as longitude,
Now I want to plot fault count (23) on gmaps for the given lat and long.

The event count in my data for city XXXX is one, I know we can plot this 1 on gmaps for given lat/long but instead of ploting this one i want to plot 23 on gmaps.

kindly note that there are no repeated cities and lat/long in my data,each row is unique.

So I cannot proceed with and geo commands.

Can anyone thing over it and help me to plot count on gmaps for given lat/long.

dmaislin_splunk
Splunk Employee
Splunk Employee

Try using iplocation and the geostats command vs. the gmaps app.

clientip=* | iplocation clientip allfields=true | geostats count by clientip

Or to see more good stuff with it:

clientip=* | iplocation clientip allfields=true | geostats translatetoxy=false count by clientip,City,Continent,Country,Region,MetroCode,Timezone,lat,lon

Or:

clientip=* | iplocation clientip allfields=true | geostats translatetoxy=false count by clientip,City,Continent,Country,Region,MetroCode,Timezone,lat,lon | table clientip * | sort - geobin
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...