Splunk Search

Splunk 6 geostats

EricksonOng
Explorer

was trying to run in geostats command and see the return result.
however keep getting the below error

WARN: Forced to skip results in geostats due to invalid latitude/longitude count='24'
WARN: Forced to skip results in geostats due to invalid latitude/longitude count='80'

have formatted the data set into the below before running the geostats command

action lat lon

Tags (2)
0 Karma

Venkat_16
Contributor

Hi Eric,
Could you please post your search query here, may be that would help sort out things

0 Karma

appleman
Contributor

If you have this field "clientip", then add "iplocation clientip" before geostats command.

e.g. sourcetype=* | iplocation clientip | geostats count by clientip

0 Karma