All Apps and Add-ons

Using the Google Maps Add-on for Splunk Enterprise, why am I getting "n/a" for all locations?

clairebesson
Explorer

Hi everyone,

I have two sources with longitude and latitude fields. I have displayed on a map longitude and latitude for these two sources :

source="source1" OR source="source2" | geostats latfield=latitude longfield=longitude count by source

Right now I have pie charts on my map, but I want markers on each location. I've read on Splunk Answers that it's only possible to do that with Google Map.
I have installed Google Map app and tried to display location for my first source:

source="source1" | geostats latfield=latitude longfield=longitude count by source

It didn't work and I had this:
alt text

Could you please help me with that ?
Thanks in advance !

0 Karma

jkat54
SplunkTrust
SplunkTrust

I think the problem is that the internal geolocation database doesnt know what location this is. In fact, google maps doesnt know either. I see google search recognizes it as a fire department's location.

So what you need to do is provide your own location field lookup.

I think once you fill in the "location" field on your own, it will show up in this table. Just a hunch though. I've never used geostats.

0 Karma

ppablo
Retired

Hi @clairebesson

I edited your post and noticed both of your searches had longfield=lontitude, but it should have been longitude. I'm not sure if that was a typo in the actual search you used if you just copy and pasted the search, or if you manually typed it out and accidentally had a typo when describing your issue in your question. If that didn't help, hopefully someone else will come along and help you further troubleshoot your issue.

0 Karma

clairebesson
Explorer

Hey ! thanks for your comment. It's a typo as I manually typed 😉

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...