Hi,
I'm getting varied results in Splunk when I investigate an IP address' location. Splunk might say "Netherlands", while multiple third-party resources might say "Estonia."
With no evidence to say one is right over the other — how frequently does Splunk update their geo cache?
Thanks
The iplocation command uses a local .mmdb file to do the lookups, which you can update yourself.
For reference: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Iplocation
The iplocation command uses a local .mmdb file to do the lookups, which you can update yourself.
For reference: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Iplocation