<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iplocation is not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485836#M135926</link>
    <description>&lt;P&gt;That address isn't in my database (I'm not updating it), but this code works for me using IP addresses that are in my database:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval ip_address="152.89.162.133" 
| iplocation ip_address
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 21 Jan 2020 17:14:13 GMT</pubDate>
    <dc:creator>efavreau</dc:creator>
    <dc:date>2020-01-21T17:14:13Z</dc:date>
    <item>
      <title>iplocation is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485835#M135925</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
iplocation is not working for some IP addresses (152.89.162.133 for example)&lt;BR /&gt;
But this IP location is in the GeoLite2 City database (checked by opening it with python)&lt;BR /&gt;
Could you tell me how to make the iplocation command working properly please?&lt;BR /&gt;
Thanks in advance and have a great day!&lt;BR /&gt;
Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 14:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485835#M135925</guid>
      <dc:creator>securiteinforma</dc:creator>
      <dc:date>2020-01-21T14:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: iplocation is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485836#M135926</link>
      <description>&lt;P&gt;That address isn't in my database (I'm not updating it), but this code works for me using IP addresses that are in my database:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval ip_address="152.89.162.133" 
| iplocation ip_address
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Jan 2020 17:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485836#M135926</guid>
      <dc:creator>efavreau</dc:creator>
      <dc:date>2020-01-21T17:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: iplocation is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485837#M135927</link>
      <description>&lt;P&gt;Hello efavreau,&lt;/P&gt;

&lt;P&gt;Thank you for your response. I tried again and it is working now. I already have restarted Splunk yesterday and it did not change anything. But maybe waiting one night has updated the configuration, I don't know.&lt;/P&gt;

&lt;P&gt;Have a nice day!&lt;BR /&gt;
Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 07:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/iplocation-is-not-working/m-p/485837#M135927</guid>
      <dc:creator>securiteinforma</dc:creator>
      <dc:date>2020-01-22T07:43:54Z</dc:date>
    </item>
  </channel>
</rss>

