Splunk Search

Can I use geostats without latitude and longitude fields in my log

iyersudh
Explorer

The application log I am working with has ISO 3166 country code but no latitude and longitude details.

With that I am able to use a choropleth using the geom command easily using featureIdFIeld=countryname but I want to also visualize a cluster map also by country. Is there a way I can use geostats on this log without having latitude and longitude? 

Labels (1)
Tags (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @iyersudh geostats command uses lat and long to plot over the map (The events are clustered based on latitude and longitude fields in the events).
without lat/long, it is impossible to work on the maps(or, maybe some apps/addons need to be designed for this task). 

everybody prefers the simple and easy route... ie, uploading/adding the lat/long lookup file to a splunk environment.

0 Karma

to4kawa
Ultra Champion

There is not the way  to geostats command without lat & long.

https://gist.github.com/sindresorhus/1341699
you should make the lookup like above.

Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...