Create a new geospatial lookup
Use your geographic feature collection file to create a new geospatial lookup in Splunk Web. For more information about geospatial lookups, see Define a geospatial lookup in Splunk Web in the Knowledge Manager Manual.
Prerequisites
- Locate and download USDM data
- Upload and configure your data
- Download a California counties shapefile
Upload the lookup file
Follow these steps to upload your geospatial feature collection file in Splunk Web:
- Unzip the
ca_counties.kmz.zip
file you downloaded in the previous step. - Navigate to Settings > Lookups.
- Under Lookup table files, click + Add new.
- Ensure the Destination app is set to Search.
- Under Upload a lookup file, click Choose File and select
ca_counties.kmz
. - Under Destination filename, enter
ca_counties.kmz
.
Configure the geospatial lookup
Follow these steps to configure your new geospatial lookup in Splunk Web:
- Click Settings > Lookups and click + Add new under Lookup definitions.
- Ensure the Destination app is set to Search.
- Under Name, enter
ca_county_lookup
. - Under Type, select Geospatial.
- Under Lookup file, select the
ca_counties.kmz
file you just uploaded. - Leave Feature Id Element blank, because this file includes the county name under the default
Placemark/name
in the .kml file. See The Feature Id Element field in the Knowledge Manager manual for more information about XML path expressions in geospatial lookups. - Click Save.
- (Optional) Test your geospatial lookup file.
- In the Search & Reporting app search bar, run the following search:
| inputlookup ca_county_lookup
If no results appear, try expanding the time range of the search. - Verify that the
featureId
field contains one row per county, and that thegeom
field contains polygons and their coordinates. Your search results table should look like the following example:count featureCollection featureId geom 0 ca_county_lookup Alameda {"type":"MultiPolygon","coordinates":[[[[-122.31109619140625, 37.8634033203125],[-122.31109619140625, 37.8634033203125]]]]} 0 ca_county_lookup Alpine {"type":"MultiPolygon","coordinates":[[[[-119.93537902832031, 38.8084831237793],[-119.93537902832031, 38.8084831237793]]]]} 0 ca_county_lookup Butte {"type":"MultiPolygon","coordinates":[[[[-121.63543701171875, 40.000885009765625],[-121.63543701171875, 40.000885009765625]]]]} 0 ca_county_lookup Calaveras "type":"MultiPolygon","coordinates":[[[[-120.21088409423828, 38.500003814697266],[-120.21088409423828, 38.500003814697266]]]]} - Select the Visualization tab and set the visualization type to Choropleth Map.
- Zoom to California by clicking the + button or double-clicking the map and verify that the county polygons are displaying properly.
- In the Search & Reporting app search bar, run the following search:
Next step
Download a California counties shapefile | Generate a choropleth map |
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2112, 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308, 9.1.2312, 9.2.2403, 9.2.2406 (latest FedRAMP release)
Feedback submitted, thanks!