Escolar Documentos
Profissional Documentos
Cultura Documentos
at/
Author: Siegfried Puchbauer
Feedback: splunk@spp.at
Google Maps for Splunk
======================
=== Documentation ===
Google Maps for Splunk allows you to easily plot any Splunk search results with
location information on a map.
== Professional Services and Support ==
This add-on has been developed by SPP (http://www.spp.at/), a Splunk Partner loc
ated in Vienna, Austria. If you require
support on getting solutions using Google Maps up and running, please contact sp
lunk@spp.at.
== Licence and Terms of Use ==
This app is licensed under the terms of the Creative Commons license and provide
d as-is without any warranty. It uses
third-party components that are licensed differently:
* Google Maps: http://code.google.com/apis/maps/terms.html
* MAXMIND GeoLite City database see http://geolite.maxmind.com/download/geoip/da
tabase/LICENSE.txt
* pygeoip see http://www.gnu.org/licenses/lgpl.html
== Using the Google Maps Search View ==
The App provides a flashtimeline-like view which allows you to simply enter a se
arch and display the results on the map.
In order to plot search results on the map they have to have some kind of locati
on information attached. This location
information has to be included in a field with the name _geo and has to be forma
tted as "<latitude>,<longitude>".
Latitude and Longitude have to be expressed as floating point numbers. As an exa
mple "47.11,0.815" would be a valid _geo
value. Other notations (like 47N 12',...) are not supported.
In most cases you don't have to build the _geo field yourself. The built-in geol
ocation lookup methods (geoip command
and geo lookup) are emitting this field by default. In cases where you already h
ave geolocation information in your
results, you can leverage the geonormalize command to build the _geo value for y
ou.
= Geolocation Lookup for IP addresses =
Performing Gelocation Lookup on external IP addresses
External IP address values can be easily translated to locations by using the bu
ilt-in geoip command or the geo lookup.
Examples:
Perform a geolocation lookup for values of the clientip field in access_combined
events:
Example:
sourcetype=device_tracking device_id=A47C08B13 | geonormalize