Splunk Enterprise Security

GeoIP not working within ES Suite

wweiland
Contributor

I have the Enterprise Security Suite App installed and working. I can run a geoip search in the Search App and that runs fine. If I try to run the same search string from the Search bar in the ES App I get a error of "Unknown search command 'geoip'" Does anyone have any suggestions on how to fix this?

Thanks,

0 Karma
1 Solution

wweiland
Contributor

Found the answer to my problem. I had to add the maps to the /opt/splunk/etc/apps/SA-AccessProtection/metadata/local.meta under the import option.

View solution in original post

0 Karma

wweiland
Contributor

Found the answer to my problem. I had to add the maps to the /opt/splunk/etc/apps/SA-AccessProtection/metadata/local.meta under the import option.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...