Yeah, similar approach as when e.g. filling a zero into a single value when there is no data.
Take the sample search from the Splunk 6 Dashboard Examples app:
| inputlookup geomaps_data.csv | iplocation device_ip | geostats latfield=lat longfield=lon count by method
That returns a bunch of geo buckets. If I modify it to return no data by adding a where 1=2
, the map disappears. By adding a little appendpipe
to the end the map is back but empty:
| inputlookup geomaps_data.csv | iplocation device_ip | where 1=2 | geostats latfield=lat longfield=lon count by method
| appendpipe [stats count | where count=0 | eval geobin = "bin_id_zl_0_y_3_x_2" | eval latitude= -10.00000 | eval logitude = -55.00000]
Yeah, similar approach as when e.g. filling a zero into a single value when there is no data.
Take the sample search from the Splunk 6 Dashboard Examples app:
| inputlookup geomaps_data.csv | iplocation device_ip | geostats latfield=lat longfield=lon count by method
That returns a bunch of geo buckets. If I modify it to return no data by adding a where 1=2
, the map disappears. By adding a little appendpipe
to the end the map is back but empty:
| inputlookup geomaps_data.csv | iplocation device_ip | where 1=2 | geostats latfield=lat longfield=lon count by method
| appendpipe [stats count | where count=0 | eval geobin = "bin_id_zl_0_y_3_x_2" | eval latitude= -10.00000 | eval logitude = -55.00000]