Splunk Search

Why are the iplocations not working at all?

robertlynch2020
Motivator

Hi

My iplocation is not working at all, what am i missing?

index=_internal sourcetype=splunkd_ui_access | stats count by clientip   | iplocation clientip

I don't get any city or country at all.

alt text

I am on Splunk Version:7.1.6 [Dec 2018], these are the files i currently have in the directory.
Do i need to update them to get this to work, or should something work by default?

alt text

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Those all IPs are private IPs (https://en.wikipedia.org/wiki/Private_network) and for private IP there are no IP location because these IP ranges are specifically reserved for Internal network.

View solution in original post

0 Karma

riddhipv
Engager

I have same issue and the IPs are public IPs too.

0 Karma

knielsen
Contributor

There are only private IP addresses in your screenshot, no public ones. There is no location lookup for private IP addresses.

The iplookup command itself works, otherwise you wouldn't get the columns for City and Country. It is just not possible to determine these for private IPs.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Those all IPs are private IPs (https://en.wikipedia.org/wiki/Private_network) and for private IP there are no IP location because these IP ranges are specifically reserved for Internal network.

0 Karma

robertlynch2020
Motivator

ok- cheers and thanks

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...