I set up a search on Splunk 6.0.1 that used the IPlocation command. In the output, I got field called CountryCode that contained a two letter country code associated with the Country. I've now upgraded to 6.2.3 and I no longer see CountryCode as part of the output when I run iplocation. What happened to CountryCode?
I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.
I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.
bawood is correct! It works to use lang=code.
I believe that is now _country_code
franks59 that field does not exist.