Splunk Search

Using multiple geospatial lookups

sigpro1911
New Member

Thanks in advance for any help.

I currently am using a geospatial file to show devices inside or outside of a geofence.

Here is a small snippet of the search

           | lookup geo_Example1 latitude longitude
           | fillnull featureId value="outsideGeoFence"
           | where LIKE(featureId, "outsideGeoFence") 
           | fillnull value="unknown" user

I can use any single geo spatial file such as Example1 Example2 Example3 that I have loaded referencing the latitude and longitude and it works as expected.

I would ideally like to add more than one geospatial lookup to the search instead of creating multiple reports or dashboards for each specific location

I have tried simply adding another lookup to the string in different ways but it is not working once I add more thane one Geospatial reference.

Tags (2)
0 Karma

DalJeanis
Legend

Basically, you just have to rename them in between lookups to get them out of the way.

        | lookup geo_Example1 latitude longitude
        | rename featureId as featureId1, user as user1
        | lookup geo_Example2 latitude longitude
        | rename featureId as featureId2, user as user2
        | lookup geo_Example3 latitude longitude
        | rename featureId as featureId3, user as user3
        | eval featureId=coalesce(featureId1,featureId2,featureId3, "outsideAllGeoFences")
        | eval user=coalesce(user1, user2,user3,"unknown")
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...