When I use the command.
SRC="*" | geoip clientip_city
I get 3055 matching events, but nothing on the map.
I guess what I expect to happen is for the IP Addresses in each of these events to show up on the Map.
What am I doing wrong?
If the field "clientip_city" contains the IP addresses, you can try this search instead:
Update: To extract the field, you have to either configure the fields to be extracted (see http://www.splunk.com/base/Documentation/latest/Knowledge/Addfieldsatsearchtime) or extract them inline:
This will extract the first matching IP in the event.