<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: * | geoip clientip returns error. HELP HELP! ___ in Security</title>
    <link>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103585#M14296</link>
    <description>&lt;P&gt;Looks like you're getting an exception that splunk doesn't know how to parse.  The main thing is it's returning failure (a nonzero exit code).  You may want to capture from inside the script how it's being invoked and run it independently to investigate.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Dec 2010 02:25:24 GMT</pubDate>
    <dc:creator>jrodman</dc:creator>
    <dc:date>2010-12-16T02:25:24Z</dc:date>
    <item>
      <title>* | geoip clientip returns error. HELP HELP! ___</title>
      <link>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103581#M14292</link>
      <description>&lt;P&gt;I did * | geoip clientip &lt;/P&gt;

&lt;P&gt;yet I get an error:&lt;/P&gt;

&lt;P&gt;"External search command 'geoip' returned error code 1.  First 1000 (of 9218) bytes of script output:" followed by the script output.&lt;/P&gt;

&lt;P&gt;A screenshot is here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://tinypic.com/r/2hnb1cp/7" rel="nofollow"&gt;http://tinypic.com/r/2hnb1cp/7&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2010 05:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103581#M14292</guid>
      <dc:creator>hunterppp</dc:creator>
      <dc:date>2010-12-11T05:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: * | geoip clientip returns error. HELP HELP! ___</title>
      <link>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103582#M14293</link>
      <description>&lt;P&gt;You can do:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;* | geoip clientip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will pipe all events in the index into the geoip tool.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2010 05:04:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103582#M14293</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-12-11T05:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: * | geoip clientip returns error. HELP HELP! ___</title>
      <link>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103583#M14294</link>
      <description>&lt;P&gt;@ftk I've updated the question with an error, any help?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2010 06:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103583#M14294</guid>
      <dc:creator>hunterppp</dc:creator>
      <dc:date>2010-12-11T06:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: * | geoip clientip returns error. HELP HELP! ___</title>
      <link>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103584#M14295</link>
      <description>&lt;P&gt;Hmm. I don't think that screenshot tells us much as to what the error is. There should be a python.log in $SPLUNK_HOME/var/log/splunk/ That should have the full error message.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2010 21:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103584#M14295</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-12-13T21:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: * | geoip clientip returns error. HELP HELP! ___</title>
      <link>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103585#M14296</link>
      <description>&lt;P&gt;Looks like you're getting an exception that splunk doesn't know how to parse.  The main thing is it's returning failure (a nonzero exit code).  You may want to capture from inside the script how it's being invoked and run it independently to investigate.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2010 02:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/geoip-clientip-returns-error-HELP-HELP/m-p/103585#M14296</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-12-16T02:25:24Z</dc:date>
    </item>
  </channel>
</rss>

