Splunk Search

Internal DB used by Splunk 6.0+ for geo details

strive
Influencer

Hi,

Could you please let me know, which internal DB is used by splunk 6.0+ for geographical details.

With out connecting to internet I am able to retrieve the City, Country, lat and lon details by using iplocation command.

Also, could you please let me know the procedure involved to update these internal DBs periodically.

Thanks

Strive

Tags (2)
1 Solution

Jason
Motivator

Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command

View solution in original post

0 Karma

Jason
Motivator

Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command

0 Karma

strive
Influencer

Yes splunk is using maxmind geo lite databases. These databases are updated for every minor release. Since maxmind databases get updated once every week (approximately) we have written python script which pulls the latest db files and replaces the older ones in our system.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...