<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding IP database to UBA in Splunk User Behavior Analytics</title>
    <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Adding-IP-database-to-UBA/m-p/591638#M47</link>
    <description>&lt;P&gt;Mapping IP addresses to geolocation can enhance your detection models with risk calculations. In UBA, this functionality is achieved using the MaxMind database.&lt;/P&gt;&lt;P&gt;UBA ships with a pre-packaged version of the GeoLite2 Free database. You can choose to download the latest version of that database and run that version instead of the pre-packaged version.&lt;/P&gt;&lt;P&gt;Perform the following steps to download the latest version of the database and run that version in UBA:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;If you update UBA, the downloaded, local version of the GeoLite2 Free database takes precedence over the pre-packaged version that ships with UBA. To use the pre-packaged version of the database you must remove the downloaded, local version.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;1. Go to &lt;A href="https://dev.maxmind.com/geoip/geoip2/geolite2/#Databases " target="_blank" rel="noopener"&gt;https://dev.maxmind.com/geoip/geoip2/geolite2/#Databases &lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. Download GeoLite2-City.mmdb.gz and unzip and copy GeoLite2-City.mmdb to the Management Node (node1) as follows:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/etc/caspida/local/conf/etl/geo-db/maxmind&lt;/LI-CODE&gt;&lt;P&gt;3. Sync cluster:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/caspida/bin/Caspida sync-cluster /etc/caspida/local/conf/etl/geo-db/&lt;/LI-CODE&gt;&lt;P&gt;4. Restart caspida:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/caspida/bin/Caspida stop-all&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;/opt/caspida/bin/Caspida start-all&lt;/LI-CODE&gt;&lt;P&gt;To learn more about IP address geolocation settings in UBA, see &lt;A href="https://docs.splunk.com/Documentation/UBA/latest/Install/Configure#Set_internal_IP_range_and_associated_office_locations" target="_blank" rel="noopener"&gt;Set internal IP range and associated office locations&lt;/A&gt;&amp;nbsp; in the &lt;EM&gt;Install and Upgrade UBA manual&lt;/EM&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 23:24:55 GMT</pubDate>
    <dc:creator>elauder_splunk</dc:creator>
    <dc:date>2022-03-30T23:24:55Z</dc:date>
    <item>
      <title>Adding IP database to UBA</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Adding-IP-database-to-UBA/m-p/591635#M46</link>
      <description>&lt;P&gt;How to manually download the IP database and add it to Splunk User Behavior Analytics (UBA)?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 23:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Adding-IP-database-to-UBA/m-p/591635#M46</guid>
      <dc:creator>elauder_splunk</dc:creator>
      <dc:date>2022-03-30T23:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Adding IP database to UBA</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Adding-IP-database-to-UBA/m-p/591638#M47</link>
      <description>&lt;P&gt;Mapping IP addresses to geolocation can enhance your detection models with risk calculations. In UBA, this functionality is achieved using the MaxMind database.&lt;/P&gt;&lt;P&gt;UBA ships with a pre-packaged version of the GeoLite2 Free database. You can choose to download the latest version of that database and run that version instead of the pre-packaged version.&lt;/P&gt;&lt;P&gt;Perform the following steps to download the latest version of the database and run that version in UBA:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;If you update UBA, the downloaded, local version of the GeoLite2 Free database takes precedence over the pre-packaged version that ships with UBA. To use the pre-packaged version of the database you must remove the downloaded, local version.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;1. Go to &lt;A href="https://dev.maxmind.com/geoip/geoip2/geolite2/#Databases " target="_blank" rel="noopener"&gt;https://dev.maxmind.com/geoip/geoip2/geolite2/#Databases &lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. Download GeoLite2-City.mmdb.gz and unzip and copy GeoLite2-City.mmdb to the Management Node (node1) as follows:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/etc/caspida/local/conf/etl/geo-db/maxmind&lt;/LI-CODE&gt;&lt;P&gt;3. Sync cluster:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/caspida/bin/Caspida sync-cluster /etc/caspida/local/conf/etl/geo-db/&lt;/LI-CODE&gt;&lt;P&gt;4. Restart caspida:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/caspida/bin/Caspida stop-all&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;/opt/caspida/bin/Caspida start-all&lt;/LI-CODE&gt;&lt;P&gt;To learn more about IP address geolocation settings in UBA, see &lt;A href="https://docs.splunk.com/Documentation/UBA/latest/Install/Configure#Set_internal_IP_range_and_associated_office_locations" target="_blank" rel="noopener"&gt;Set internal IP range and associated office locations&lt;/A&gt;&amp;nbsp; in the &lt;EM&gt;Install and Upgrade UBA manual&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 23:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Adding-IP-database-to-UBA/m-p/591638#M47</guid>
      <dc:creator>elauder_splunk</dc:creator>
      <dc:date>2022-03-30T23:24:55Z</dc:date>
    </item>
  </channel>
</rss>

