Splunk® Enterprise

Dashboards and Visualizations

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. Click here for the latest version.
Acrobat logo Download topic as PDF

Cluster maps

Use the cluster map visualization to plot aggregated values on a map.

Viz ItalyMap3.png

Data formatting

To generate a cluster map, use the geostats command. The geostats command generates events that include latitude and longitude coordinates for markers. It is similar to the stats command, but provides options for zoom levels and cells for mapping.

For more information, see geostats in the Search Reference.

Configuration options

Use the Format menu to adjust the following cluster map components.

  • Tile appearance and source
  • Cluster marker appearance
  • Zoom on scroll behavior


You can also enable or disable cluster map drilldown in the Format menu.

Cluster map drilldown lets users open a secondary search by clicking on a map cluster. The secondary search uses the geographic boundaries of the selected cluster.


The following search generates a map showing California earthquakes of magnitude greater than 3 for the past 30 days.

index=main mag>3 | geostats latfield=latitude longfield=longitude count

Viz drilldownMap.png

When a user clicks on a cluster indicating earthquake data, a search launches using the latitude and longitude boundaries of that cluster.

index=main mag>3 | search latitude>=36.21094 latitude<36.56250 longitude>=-122.34375 longitude<-121.64062
Last modified on 23 March, 2017
Configure a Choropleth map
Dashboard overview

This documentation applies to the following versions of Splunk® Enterprise: 6.5.7

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters