Splunk Search

Internal DB used by Splunk 6.0+ for geo details

strive
Influencer

Hi,

Could you please let me know, which internal DB is used by splunk 6.0+ for geographical details.

With out connecting to internet I am able to retrieve the City, Country, lat and lon details by using iplocation command.

Also, could you please let me know the procedure involved to update these internal DBs periodically.

Thanks

Strive

Tags (2)
1 Solution

Jason
Motivator

Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command

View solution in original post

0 Karma

Jason
Motivator

Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command

0 Karma

strive
Influencer

Yes splunk is using maxmind geo lite databases. These databases are updated for every minor release. Since maxmind databases get updated once every week (approximately) we have written python script which pulls the latest db files and replaces the older ones in our system.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...