Splunk Search

Is there a way to enrich events by having country information from IP address automatically through props.conf?

efheem
Explorer

Hello,

I am trying to come-up with something which will automatically enrich the events using the country information using the src_ip field in the events. I understand that the iplocation command can do this in search time. Is there any way we can get this done automatically using props.conf? I am expecting to have a lookup file which we can leverage to achieve this and I cannot find any.

Cheers.

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...