I'm running the next query in my Splunk:
index="traffic_violations_index"
| geostats latfield=Latitude longfield=Longitude count by arrest_type
Results are shown in a map correctly, but there is the next warn in my dashboard: "Forced to skip results in geostats due to invalid latitude/longitude count='20'"
Does anybody know how to avoid this warn? I don't find anything about it in splunk docs.
Thanks in advance.
It may be due to incorrect value of long or lat . Try to use ->This app will be helpful:
https://splunkbase.splunk.com/app/3124/