Splunk Search

iplocation when outputting in command stats

nalia_v
Loves-to-Learn Everything

Hello everyone,
Someone may already be doing the output of grouped events with the definition of location by ip.

How not to lose location data when grouping events ?location.png

In my request spl it is

| search......
|stats count(tunnelid) as sessioncount, values(StartTime) as StartTime, values(tunnelid) as tunnelid, values(tunnelip) as tunnelip, values(remip) as remip, values(vendor_action) as vendor_action by user
| iplocation remip

Of course, when displaying one type, the location IP is displayed.

How to display data on the location of each IP in grouped events ?

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Apparently, the iplocation command can't handle a multi-value field.  Try putting iplocation before stats.

| search......
| iplocation remip
| stats count(tunnelid) as sessioncount, values(*) as * by user

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...