Hi,
Could you please let me know, which internal DB is used by splunk 6.0+ for geographical details.
With out connecting to internet I am able to retrieve the City, Country, lat and lon details by using iplocation
command.
Also, could you please let me know the procedure involved to update these internal DBs periodically.
Thanks
Strive
Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.
http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command
Sounds like it is maxmind (perhaps maxmind lite) and updated with maintenance releases of Splunk.
http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command
Yes splunk is using maxmind geo lite databases. These databases are updated for every minor release. Since maxmind databases get updated once every week (approximately) we have written python script which pulls the latest db files and replaces the older ones in our system.