Splunk Search

How to map every event which has a lat and long field?

jdunlea
Contributor

I have 35 events. Each one has a lat and long field. How do I map each one of them to an individual point on a map? When I use geostats, it keeps trying to throw things into "geo bins".

0 Karma

DalJeanis
Legend
0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

Make sure you reference the latfield and longfield with geostats:

sourcetype=foo
| geostats latfield=my_laitudet_field longfield=my_longitude_field count

Otherwise, Splunk will just look for fields called lat and lon. As @mtranchita mentioned, make sure you're on the visualizations tab and have selected the appropriate visualization type.

Note where it says "Cluster Map" as the visualization type:alt text

mtranchita
Communicator

I'm likely misunderstanding the question, but are you looking at the statics tab and not the visualization - or can you change the visualization type?
I think that the example from the command reference shows what you are describing.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...