Dashboards & Visualizations

Creating a table in the google app (geo ip)

Michael_Schyma1
Contributor
sourcetype=SidewinderFirewall NOT rule_name="Global__deny_all" srcburb=external dstport=3389 | lookup geo ip as srcip 

I am trying to create a TABLE using the google application to show a count by srcip and also show the source IP next to it. So in the table I want to have a count, srcip, and the geolocation of that src IP. I am just not 100% sure how to create this type of a table in google app. Everytime i use the 'table' or 'top' function in the application no results are returned.

Any suggestions?

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

I tried this in my system with access log data and it came up fine. Does this work for you. If you want to view the _geo field, you'll need to create a new field for it using eval before using table, stats commands. I went into Views->Sample Search and pasted in my search.

sourcetype=access_combined | lookup geo ip as clientip | eval myGeo=_geo | stats count by myGeo,clientip

sdaniels
Splunk Employee
Splunk Employee

Not sure what you mean by geo results tab. If you go to Views->Sample Search then paste in your results. you don't see anything? What about without everything after the lookup

0 Karma

Michael_Schyma1
Contributor

When I change it to this:

sourcetype=SidewinderFirewall NOT rule_name="Global__deny_all" srcburb=external dstport=3389 | lookup geo ip as srcip | eval myGeo=_geo | stats count by myGeo,srcip

or when i use your search, i am still not getting any information in the geo results tab which i am guessing is the table, but when i go to events i do see logs coming through.

0 Karma

Michael_Schyma1
Contributor

Thank you so much, Ill give it a shot and see if i can get it to work

0 Karma

sdaniels
Splunk Employee
Splunk Employee

You see the eval statement I have. In order to display that lat/long detail in a table you can't reference _geo, you need to create it as a new field using eval.

0 Karma

Michael_Schyma1
Contributor

I am not sure what you mean by save the _geo field first. Could you explain that for me?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...