Splunk Search

In Splunk 6.2.3, what happened to the CountryCode field that was part of the output from using the iplocation command in Splunk 6.0.1?

jedatt01
Builder

I set up a search on Splunk 6.0.1 that used the IPlocation command. In the output, I got field called CountryCode that contained a two letter country code associated with the Country. I've now upgraded to 6.2.3 and I no longer see CountryCode as part of the output when I run iplocation. What happened to CountryCode?

0 Karma
1 Solution

bawood
Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

View solution in original post

bawood
Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

jedatt01
Builder

bawood is correct! It works to use lang=code.

franks59
Explorer

I believe that is now _country_code

0 Karma

cmlombardo
Path Finder

franks59 that field does not exist.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...