All Apps and Add-ons

Location Tracker - showtraces didn't work

obrosch
Path Finder

Hi,

I tried to send different geolocations with different timestamps and one driver to see a trace of the route of our driver. But it didn't work. I can't see a trace. I send following example data to the index:

date;LAT;LON;DRIVER
2017-11-28 16:30:45;51.093511;9.549121;0815
2017-11-28 16:33:45;50.904731;9.444201;0815
2017-11-28 16:38:45;51.143050;9.257047;0815
2017-11-28 17:00:00;52.363053;13.502228;0815
2017-11-28 17:45:00;52.551258;13.294692;0815
2017-11-28 17:50:15;52.537081;13.263395;0815
2017-11-28 18:00:00;52.528005;13.274333;0815
2017-11-28 18:05:00;52.511196;13.301656;0815
2017-11-28 18:10:00;52.487449;13.331712;0815
2017-11-28 18:15:00;52.429807;13.524335;0815

And I thought I can see many points where the driver was. But I only see a marker on the last point.

Kind regards for your help.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

There is a parameter in the location tracker format configuration how many seconds apart points can be in order to still draw a connection - looking at your data, I'm pretty sure that setting needs to be increased for your data... possibly to 11 minutes or so, assuming you're supposed to get data every five minutes then one missing point would still lead to a connection but more missing points would be visible on the map as a gap.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

There is a parameter in the location tracker format configuration how many seconds apart points can be in order to still draw a connection - looking at your data, I'm pretty sure that setting needs to be increased for your data... possibly to 11 minutes or so, assuming you're supposed to get data every five minutes then one missing point would still lead to a connection but more missing points would be visible on the map as a gap.

obrosch
Path Finder

Graet Martin,

that was my problem. I didn't see that this is in seconds. Now I changed it to 86400 and I can see everything.
Perfect.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...