<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maxmind | Use 5 different mmdb databases in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618375#M14317</link>
    <description>&lt;P&gt;Yes, you can continue to use your existing MMDB file.&amp;nbsp; It will, of course, become outdated eventually.&lt;/P&gt;&lt;P&gt;If you want to use a new MMDB provider then just install the file as documented at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Iplocation#Updating_the_IP_geolocation_database_file" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Iplocation#Updating_the_IP_geolocation_database_file&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 12:29:21 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-10-26T12:29:21Z</dc:date>
    <item>
      <title>Maxmind | How to use 5 different mmdb databases?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/615984#M14111</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi splunkers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have problem about usind maxming geoip datavbses&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I get 4 databases from maxmind (&lt;SPAN&gt;GeoIP2-City.mmdb;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;GeoLite2-ASN.mmdb;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;GeoIP2-Country.mmdb; GeoIP2-Anonymous-IP.mmdb)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I need to use these 4 databases&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Following the html documentation about iplocation (&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Iplocation" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Iplocation&lt;/A&gt;&lt;SPAN&gt;), I copy the databases I need to use under a specific directory and configure limits.conf to point to this directory for any of the databases I need to use.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This database was copied over search Head AND Indexers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Limits.conf :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[root@vlpsospk04-sh databases]# more ../local/limits.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[iplocation]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;db_path = /data/splunk/etc/apps/cnaf_deploy_maxmind_databases/databases/GeoIP2-City.mmdb&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;db_path = /data/splunk/etc/apps/cnaf_deploy_maxmind_databases/databases/GeoLite2-ASN.mmdb&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;db_path = /data/splunk/etc/apps/cnaf_deploy_maxmind_databases/databases/GeoIP2-Country.mmdb&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;db_path = /data/splunk/etc/apps/cnaf_deploy_maxmind_databases/databases/GeoIP2-Anonymous-IP.mmdb&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then, when I m using this file configuration, Then restart splunkd process, I get data about GeoIP2-City.mmdb, but nothing about GeoIP2-Anonymous-IP.mmdb as an exemple.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the documentation about iplocation, only one mmdb file is documented, so is this a specific configuration to use multiple mmd files ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Does someone get results with sevferal databases ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 00:36:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/615984#M14111</guid>
      <dc:creator>o_calmels</dc:creator>
      <dc:date>2022-10-27T00:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/615987#M14112</link>
      <description>&lt;P&gt;Splunk only supports a single iplocation file, usually GeoIP2-City.mmdb.&amp;nbsp; Furthermore, Splunk recently changed geo-ip providers and no longer ships with a MaxMind database.&lt;/P&gt;&lt;P&gt;Make a case for supporting all four databases at&amp;nbsp;&lt;A href="https://ideas.splunk.com" target="_blank"&gt;https://ideas.splunk.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 13:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/615987#M14112</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-05T13:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618371#M14316</link>
      <description>&lt;P&gt;What about the deployments where Splunk is already using mmdb database. Those can still continue?&lt;/P&gt;&lt;P&gt;And if want to move to the new one, is there any doc yet?&lt;/P&gt;&lt;P&gt;Thanks in Advance..&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 12:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618371#M14316</guid>
      <dc:creator>NDabhi21</dc:creator>
      <dc:date>2022-10-26T12:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618375#M14317</link>
      <description>&lt;P&gt;Yes, you can continue to use your existing MMDB file.&amp;nbsp; It will, of course, become outdated eventually.&lt;/P&gt;&lt;P&gt;If you want to use a new MMDB provider then just install the file as documented at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Iplocation#Updating_the_IP_geolocation_database_file" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Iplocation#Updating_the_IP_geolocation_database_file&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 12:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618375#M14317</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-26T12:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618390#M14318</link>
      <description>&lt;P&gt;If you have on-prem Splunk, you can look into this add-on (&lt;A href="https://splunkbase.splunk.com/app/6169" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/6169&lt;/A&gt;). For Splunk Cloud, the most straight forward way is to download the Maxmind databases in CSV and create a lookup definition for it.&lt;/P&gt;&lt;P&gt;For example, to configure the Geolite-ASN lookup definition you want to set the match type to CIDR(network) and maximum match to 1.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="johnhuang_0-1666790972461.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22153iAD92B8DDD1056C66/image-size/medium?v=v2&amp;amp;px=400" role="button" title="johnhuang_0-1666790972461.png" alt="johnhuang_0-1666790972461.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 13:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618390#M14318</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-26T13:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618505#M14322</link>
      <description>&lt;P&gt;Write your own external lookup command in python that uses the maxmind python library per mmdb as each one has different data. You will want to work with your system administrators to out of Splunk sync tge mmbd files to disk and your code point to tge files there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 23:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/618505#M14322</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2022-10-26T23:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | How to use 5 different mmdb databases?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/641275#M16177</link>
      <description>&lt;P&gt;Did you deploy from the CM to all your index servers og just copy direct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 12:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/641275#M16177</guid>
      <dc:creator>jnhth</dc:creator>
      <dc:date>2023-04-25T12:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | How to use 5 different mmdb databases?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/641284#M16178</link>
      <description>&lt;P&gt;You can check out IPinfo as an alternative. We have an app that supports our API and Database both on Splunk.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4070" target="_blank"&gt;https://splunkbase.splunk.com/app/4070&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Our databases come in MMDB format as well.&amp;nbsp;We offer a free country + ASN database that you can try out with the Splunk app now.:&amp;nbsp;&lt;A href="https://ipinfo.io/developers/ip-to-country-asn-database" target="_blank"&gt;https://ipinfo.io/developers/ip-to-country-asn-database&lt;/A&gt;,&amp;nbsp;and we offer a free IP geolocation API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 13:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/641284#M16178</guid>
      <dc:creator>reincoder</dc:creator>
      <dc:date>2023-04-25T13:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659328#M17492</link>
      <description>&lt;P&gt;Hello Rich,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;"Furthermore, Splunk recently changed geo-ip providers and no longer ships with a MaxMind databas&lt;/EM&gt;e."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What company is now the Splunk geo-ip DB provider, in 2023, since Splunk no longer ships with a MaxMind database as you mentioned?&lt;/P&gt;&lt;P&gt;Also, what is the new DB file name, what directory is it located in, and does the new iplocation DB get updated after the initial SE installation, or not ?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Dennis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 18:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659328#M17492</guid>
      <dc:creator>Dennis</dc:creator>
      <dc:date>2023-10-02T18:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659339#M17494</link>
      <description>&lt;P&gt;Don't know about the provider but the database is updated only on Splunk upgrades. You can do manual updates but they will be overwritten when you upgrade your Splunk installation unless you set a custom path to the database file.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 21:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659339#M17494</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-02T21:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659362#M17496</link>
      <description>&lt;P&gt;Thanks Rick!&lt;/P&gt;&lt;P&gt;What Rich Galloway stated was that "&lt;STRONG&gt;&lt;EM&gt;Splunk recently changed geo-ip providers and no longer ships with a MaxMind databas&lt;/EM&gt;e."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If that is the case, I was asking what company is the new geo-ip provider that has taken over from MaxMind ?&lt;/P&gt;&lt;P&gt;Also, what version of SE did the switchover over, and what directory is the new geo-IP DB in, and what is the new mmdb file name?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Dennis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 23:56:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659362#M17496</guid>
      <dc:creator>Dennis</dc:creator>
      <dc:date>2023-10-02T23:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659434#M17500</link>
      <description>&lt;P&gt;Splunk hasn't disclosed the new vendor of geo-ip data, which changed with version 9.0.&lt;/P&gt;&lt;P&gt;The file is $SPLUNK_HOME/share/dbip-city-lite.mmdb.&lt;/P&gt;&lt;P&gt;You can read more about it in the &lt;FONT face="courier new,courier"&gt;iplocation&lt;/FONT&gt; documentation at &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Iplocation" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Iplocation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 13:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659434#M17500</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-03T13:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659446#M17504</link>
      <description>&lt;P&gt;Thanks Rich!&lt;/P&gt;&lt;P&gt;That answered all my questions, but brought up 2 new questions.&lt;/P&gt;&lt;P&gt;We are running SE 9.0.5 so we have the new&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;$SPLUNK_HOME/share/dbip-city-lite.mmdb&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt; geo-location DB as you mentioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The reason for this new question is I noticed an IP address yesterday whose City seems to be outdated against the results from iplocation.net.&lt;/P&gt;&lt;P&gt;Guessing there is no way to update the new&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;dbip-city-lite.mmdb&lt;/FONT&gt; &lt;/STRONG&gt;DB after the initial SE install since Splunk has not divulged the vendor ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Went to the link you provided, and to the 9.0.5 page for iplocation which does state the new vendor's mmdb file name, but the data after that shows how to update MaxMind DB's,&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;GeoLite2-City.mmdb &amp;amp;&amp;nbsp;GeoIP2-City.mmdb&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;, which as you said were replaced in 9.0.0, and are not shipped with version 9.0.5.&amp;nbsp; Is this an oversight in the documentation ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.5/SearchReference/Iplocation" target="_blank" rel="noopener"&gt;iplocation - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;H2&gt;&lt;EM&gt;&lt;SPAN class=""&gt;"Usage&lt;/SPAN&gt;&lt;/EM&gt;&lt;/H2&gt;&lt;P&gt;&lt;EM&gt;The&amp;nbsp;iplocation&amp;nbsp;command is a distributable streaming command. See&amp;nbsp;&lt;A class="" href="http://docs.splunk.com/Documentation/Splunk/9.0.5/SearchReference/Commandsbytype" target="_blank" rel="noopener"&gt;Command types&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The Splunk software ships with a copy of the &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;dbip-city-lite.mmdb&lt;/FONT&gt;&lt;/STRONG&gt; IP geolocation database file. This file is located in the $SPLUNK_HOME/share/ directory.&lt;/EM&gt;&lt;/P&gt;&lt;H3&gt;&lt;EM&gt;&lt;SPAN class=""&gt;Updating the IP geolocation database file&lt;/SPAN&gt;&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;Through Splunk Web, you can update the .mmdb file that ships with the Splunk software. The file you update it with can be a copy of one of the following two files. Only those two files are supported. To use these two files, you must have a license for the &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GeoIP2 City database.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;File name Description&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;GeoLite2-City.mmdb&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;EM&gt;This is a free IP geolocation database that is updated on its download page on a weekly basis.&lt;/EM&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;GeoIP2-City.mmdb&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;EM&gt;This is a paid version of the &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GeoLite2-City IP geolocation database &lt;/FONT&gt;&lt;/STRONG&gt;that is more accurate than the free version.&lt;/EM&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;EM&gt;Replacing your mmdb file with one of these two files reintroduces the Timezone field that is absent in the default .mmdb file, but does not reintroduce the MetroCode field.&lt;/EM&gt;&lt;/P&gt;&lt;H4&gt;&lt;EM&gt;&lt;SPAN class=""&gt;Prerequisites&lt;/SPAN&gt;&lt;/EM&gt;&lt;/H4&gt;&lt;P&gt;&lt;EM&gt;You must have a&amp;nbsp;&lt;STRONG&gt;&lt;A title="Splexicon:Role" href="https://docs.splunk.com/Splexicon:Role" target="_blank" rel="noopener noreferrer"&gt;role&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;with the upload_mmdb_files&amp;nbsp;&lt;STRONG&gt;&lt;A title="Splexicon:Capability" href="https://docs.splunk.com/Splexicon:Capability" target="_blank" rel="noopener noreferrer"&gt;capability&lt;/A&gt;&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;H4&gt;&lt;EM&gt;&lt;SPAN class=""&gt;Steps&lt;/SPAN&gt;&lt;/EM&gt;&lt;/H4&gt;&lt;OL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;EM&gt;Go online and find a download page for the binary .tar.gz versions of the &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GeoLite2-City&lt;/FONT&gt; &lt;/STRONG&gt;or the &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GeoIP2-City&lt;/FONT&gt; &lt;/STRONG&gt;database files.&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;EM&gt;Download the binary .tar.gz version of the file (&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GeoLite2-City or GeoIP2-City)&lt;/FONT&gt;&lt;/STRONG&gt; that is most appropriate for your needs.&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;EM&gt;Expand the binary .tar.gz version of the file.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;The .tar.gz file expands into a folder which contains the &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GeoLite2-City.mmdb file, or the GeoIP2-City.mmdb file,&lt;/FONT&gt; &lt;/STRONG&gt;depending on the download you selected.&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;EM&gt;In Splunk Web, go to&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Lookups &amp;gt; GeoIP lookups file&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;EM&gt;On the GeoIP lookups file page, click&amp;nbsp;&lt;STRONG&gt;Choose file&lt;/STRONG&gt;. Select the .mmdb file.&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;EM&gt;Click&amp;nbsp;&lt;STRONG&gt;Save&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;The page displays a success message when the upload completes."&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 14:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659446#M17504</guid>
      <dc:creator>Dennis</dc:creator>
      <dc:date>2023-10-03T14:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659449#M17505</link>
      <description>&lt;P&gt;You can replace the geo-ip file with an MMDB file from any vendor, including MaxMind.&amp;nbsp; It does not have to be from the same vendor as the one that shipped with Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 14:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659449#M17505</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-03T14:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659451#M17506</link>
      <description>&lt;P&gt;Great, thanks Rich.&lt;/P&gt;&lt;P&gt;It would be good if Splunk could enable the new geo-location DB that ships with SE 9.0.0 or later,&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;dbip-city-lite.mmdb,&lt;/FONT&gt;&lt;/STRONG&gt; to be updated on a regular basis instead of having to replace the new DB with either MaxMind's, or some other vendor's DB.&lt;/P&gt;&lt;P&gt;Splunk could build that update functionality in behind the scenes if divulging the new vendor is top secret for some reason.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Otherwise, the update procedure for the new DB could be added to the iplocation page like for MaxMind's update procedure.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 14:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659451#M17506</guid>
      <dc:creator>Dennis</dc:creator>
      <dc:date>2023-10-03T14:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind | Use 5 different mmdb databases</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659456#M17507</link>
      <description>&lt;P&gt;Consider putting that into Feedback on the docs page and submitting it at &lt;A href="https://ideas.splunk.com" target="_blank"&gt;https://ideas.splunk.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 15:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Maxmind-How-to-use-5-different-mmdb-databases/m-p/659456#M17507</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-03T15:22:42Z</dc:date>
    </item>
  </channel>
</rss>

