splunkcto
Joined: 06/10/2012 16:29:15
Messages: 1
Offline
|
I have a big pile of coordinates from a Splunk search job. (each event has lat/lon and i want to add Postal Code to them. In Splunk this enrichment is called a "lookup").
Is it possible to in a single request, send Geonames a JSON or XML object that contains a number of records and have the resulting request sent back with the "answers". Otherwise, it seems entirely possible that I could end up sending thousands to hundreds of thousands of requests (and running in to limits).
I am fine with purchasing premium services.
(or, would you recommend I just download the postal code dataset?)
-michael wilde
--splunk
|