index=XXXX eventtype=XXXXX | iplocation src_ip | geostats globallimit=0 count by src_ip
its not working
Field I have in result is src_city which consist of city names
Hello there,
take a look at this answer:
https://answers.splunk.com/answers/148542/how-to-plot-data-on-the-splunk-map-from-lookup-data-using-...
you can find a table online that has cities and geolocation coordinates, save as a lookup and refer to it in your search
hope it helps
Hello there,
take a look at this answer:
https://answers.splunk.com/answers/148542/how-to-plot-data-on-the-splunk-map-from-lookup-data-using-...
you can find a table online that has cities and geolocation coordinates, save as a lookup and refer to it in your search
hope it helps