Hello, Im very new with Splunk. Can you please tell me what is missing on my search string
eventtype=security * user_Type=INT user_Organization="BODI" | top limit=20 user_Location | rename user_Location as Site | fields - percent |geom geo_countries featureIdField=count
I need to show the values on my map however it is showing blank and no colors. Please help.
To plot results on a map, the events need to contain latitude and longitude, which your query appears to be missing. Add those fields to your query, if you have them. If you don't have those fields, you can use the iplocation
command to derive latitude and longitude from an IP address. Then use geostats
to plot the results.
eventtype=security * user_Type=INT user_Organization="BODI" | top limit=20 user_Location | rename user_Location as Site | fields - percent | iplocation foo | geostats count by Site
eventtype=security * user_Type=INT user_Organization="BODI" | top limit=20 user_Location | rename user_Location as Site | fields count Site |geom geo_countries featureIdField=Site
Use featureIdField
as Site
To plot results on a map, the events need to contain latitude and longitude, which your query appears to be missing. Add those fields to your query, if you have them. If you don't have those fields, you can use the iplocation
command to derive latitude and longitude from an IP address. Then use geostats
to plot the results.
eventtype=security * user_Type=INT user_Organization="BODI" | top limit=20 user_Location | rename user_Location as Site | fields - percent | iplocation foo | geostats count by Site