When I use the command.
SRC="*" | geoip clientip_city
I get 3055 matching events, but nothing on the map.
I guess what I expect to happen is for the IP Addresses in each of these events to show up on the Map.
What am I doing wrong?
you're right, it's not there, how do I get it there?
seems like you don't have the clientip_city field extracted. When you execute the search in the default search view of Splunk, are you able to see the field in the field picker (on the left side)?
that gave "0 matching events" and nothing on the map either