Splunk Search

How do I display a blank map using geostats?

dzilk
Engager

When I run a search to be displayed on a map using geostats that does not include any returned data, the map doesn't display. Instead it just indicates "Search was cancelled". I would like it to display a blank map instead. Is this possible?

Tags (1)
0 Karma

paramagurukarth
Builder

Another option is there....
append an empty row to the end just with latitude and longitude value alone (before calling geostats)

to know how to append empty row please see the below link
http://answers.splunk.com/answers/41525/add-a-row-to-end-of-table.html

0 Karma

Venkat_16
Contributor

Hi paramagurukarthikeyan !<

are u using postprocess search in your Map Dashboard?

0 Karma

paramagurukarth
Builder

No I am using a custom search command and all our geo information are updated through that command( Based on IP address)
So when no geo information is available I pass dummy value for map fields.

Similarly when there are no results before geostats, pass an empty record (Event) with 0.0000 lat and 0.000 lon and all other values as "-"

0 Karma

paramagurukarth
Builder

How you are forming the latitude and longitude for your map?
If you are using any separate program to return longitude and latitude using your Client IP any other values means ... return an empty record (Event) with 0.0000 lat and 0.000 lon and all other values as "-"

0 Karma

neogeek83
New Member

I don't believe so, at least, I haven't seen a way to do it. Latest version has updated the text to be "No Results yet found," until it finishes the search and then displays "No Results found."

Would be much better to have a blank map with notice overlaid with the "No Results found."

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...