Splunk Search

iplocation draws blank

gesman
Communicator

This doesn't returns anything:
| stats c | eval ip="107.181.233.178" | iplocation ip allfields=1 | table ip, Country, Region, City
likely due to iplocation's usage of limited geoip DB?

Is there a way (perhaps for an extra fee?) to plug into Splunk more robust and rich IP location and assignment resolution capabilities?

Tags (1)
0 Karma

joshd
Builder

You should reference this already answered question which will be what you need...

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command.html

gesman
Communicator

Thanks much, that thread is a good info.

Gleb

0 Karma

joshd
Builder

No problem, dont forget to mark the question as answered. Cheers.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...