All Apps and Add-ons

Is it ok to blacklist the .dat files included in the MAXMIND app?

jfreund
Explorer

They're quite huge (totalling over 70MB) and I've been looking into reducing our knowledge bundle size. From the app description the app's processing is performed on the search heads so I am guessing the files aren't needed on the indexers, so I'm wondering if it's ok to blacklist this app from being included in the knowledge bundle.

0 Karma

myron_davis
Path Finder

I don't ship out the maxmind database via search bundles.

I use the system maxmind database; if you run debian and install the package geoip-database-contrib; each machine that has that package will be kept auto-up-to-date and if you modify each python script to point to the system maxmind database there is no need to worry about blacklists and the search bundle getting too large.

for example:
asn.py
DB_PATH = os.path.join('/usr','share','GeoIP','GeoIPASNum.dat')

Done; never worry about large search bundles or updated maxmind databases again!,What I've done is edit the lookup script to point to the system maxmind database.

0 Karma

somesoni2
Revered Legend

I guess that will only be required where searches are executed, e.g. Search Head and Job Servers (if you have dedicated instances for jobs/saved searches/alerts), So it should be OK to exclude them from Indexer instance package.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...