<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GeoLite IPLocation discrepancy in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482875#M135237</link>
    <description>&lt;P&gt;Good Morning! (or whatever time of day it is where you are). I actually found the answer after I delved a bit deeper into some other related Splunk Answers posts - I didn't realize that the file also needed to be updated on the indexers. Once it was updated, the search returned with the expected [correct] results.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2020 12:29:41 GMT</pubDate>
    <dc:creator>mbraiman</dc:creator>
    <dc:date>2020-02-26T12:29:41Z</dc:date>
    <item>
      <title>GeoLite IPLocation discrepancy</title>
      <link>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482872#M135234</link>
      <description>&lt;P&gt;Good Afternoon everyone!&lt;/P&gt;

&lt;P&gt;We seem to be encountering a discrepancy with our IPLocation database.  We're running Splunk 7.3.3 and recently updated the GeoLite  lookup in /opt/splunk/share.  We noticed a discrepancy however between what the MaxMind's mmdb file returns and what other online IP lookups show.  The IP in question shows as a London/U.K based IP in online engines (including MaxMind's own lookup.)  However Splunk's iplocation function labels it as an Italy-based address with appropriate Lat/Lon values.  I'm at a loss as to what'd be causing this apparent mismatch.  Any insight/experiences as to what's causing this problem are appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 18:39:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482872#M135234</guid>
      <dc:creator>mbraiman</dc:creator>
      <dc:date>2020-02-25T18:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: GeoLite IPLocation discrepancy</title>
      <link>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482873#M135235</link>
      <description>&lt;P&gt;Hi mbraiman, &lt;/P&gt;

&lt;P&gt;Please provide some sample events that will result in the wrong location as well as the &lt;STRONG&gt;complete&lt;/STRONG&gt; SPL used on these events, and the version of the MaxMind's mmdb file you used.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 20:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482873#M135235</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2020-02-25T20:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: GeoLite IPLocation discrepancy</title>
      <link>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482874#M135236</link>
      <description>&lt;P&gt;Thanks for the reply MuS - I didn't realize that the mmdb file needed to be updated on each of our indexers as well as the search head.  Once that was done the iplocation function mapped the events as we expected them.  Thanks for your reply!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 12:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482874#M135236</guid>
      <dc:creator>mbraiman</dc:creator>
      <dc:date>2020-02-26T12:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: GeoLite IPLocation discrepancy</title>
      <link>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482875#M135237</link>
      <description>&lt;P&gt;Good Morning! (or whatever time of day it is where you are). I actually found the answer after I delved a bit deeper into some other related Splunk Answers posts - I didn't realize that the file also needed to be updated on the indexers. Once it was updated, the search returned with the expected [correct] results.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 12:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/GeoLite-IPLocation-discrepancy/m-p/482875#M135237</guid>
      <dc:creator>mbraiman</dc:creator>
      <dc:date>2020-02-26T12:29:41Z</dc:date>
    </item>
  </channel>
</rss>

