Splunk Search

Internal DB used by Splunk 6.0+ for geo details

strive
Influencer

Hi,

Could you please let me know, which internal DB is used by splunk 6.0+ for geographical details.

With out connecting to internet I am able to retrieve the City, Country, lat and lon details by using iplocation command.

Also, could you please let me know the procedure involved to update these internal DBs periodically.

Thanks

Strive

Tags (2)
1 Solution

Jason
Motivator

Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command

View solution in original post

0 Karma

Jason
Motivator

Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command

0 Karma

strive
Influencer

Yes splunk is using maxmind geo lite databases. These databases are updated for every minor release. Since maxmind databases get updated once every week (approximately) we have written python script which pulls the latest db files and replaces the older ones in our system.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...