Dashboards & Visualizations

Choropleth Map with values instead of count

bosch_softtec
Path Finder

Hi,
I like to setup a choropleth map but I'm not able to build this map by the vales of a zone. I only got it working by counting the country's which results in value=1.

My search looks like:

| inputcsv Region.csv  | join max=0 Region [inputcsv ISO_3166_Codes_Lat_Long.csv ] | stats count by Country | geom geo_countries featureIdField="Country"

Region.csv file contains the country code and the number of clients. It looks like:

Region,Number
DE,51
GB,154
US,197

After the join I get all needed informations to setup the map but the result is:

Country        | count | ...
Germany        | 1     | ...
United Kingdom | 1     | ...
United States  | 1     | ...

I like to get:

Country        | count | ...
Germany        | 51    | ...
United Kingdom | 154   | ...
United States  | 197   | ...

I tried it with:

| inputcsv Region.csv  | join max=0 Region [inputcsv ISO_3166_Codes_Lat_Long.csv ] | stats values(Number) by Country | geom geo_countries

But the map won't be coloured.

Any idea how to solve this?

Thank's for your ideas and help
Best regards
Thorsten

Tags (1)
0 Karma
1 Solution

gokadroid
Motivator

Since I don't have the data to plot similar stuff but If there is only one Number value per country you can you please try this and see if it works out:

...| chart max(Number) by Country | geom geo_countries featureIdField="Country"

View solution in original post

0 Karma

bosch_softtec
Path Finder

Hi gokadroid, thanks for you answer, it's working 🙂

gokadroid
Motivator

Since I don't have the data to plot similar stuff but If there is only one Number value per country you can you please try this and see if it works out:

...| chart max(Number) by Country | geom geo_countries featureIdField="Country"
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...