<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MaxMind DB Usage (more than just City) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536767#M151751</link>
    <description>&lt;P&gt;to4kawa,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lookups may be a possibility, but it's beyond my skill level and it adds layers of complication to the maintenance....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Updates come out weekly&lt;/P&gt;&lt;P&gt;2. There are 2 csv files per 1 mmdb file (6 csv files, 3 mmdb files), which will require a total of 6 lookups to maintain and run queries against&lt;/P&gt;&lt;P&gt;3. The csv files / mmdb's utilize subnet ranges (IPV4 &amp;amp; IPV6 address ranges).....1.0.64.0/24, 78.129.0.0/17, 185.91.188.0/22, 2001:218:3000::/46, 2001:410:80::/37, 2a00:df0::/32, 2a04:f580:9240::/48&lt;/P&gt;&lt;P&gt;4. The csv files utilize both IPV4 and IPV6 addresses&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm totally open to suggestions, though. &amp;nbsp;Thanks!!&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 00:13:52 GMT</pubDate>
    <dc:creator>frog22</dc:creator>
    <dc:date>2021-01-22T00:13:52Z</dc:date>
    <item>
      <title>MaxMind DB Usage (more than just City): How to store and link DBs?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536042#M151544</link>
      <description>&lt;P&gt;All,&lt;/P&gt;
&lt;P&gt;Hopefully I have this in the correct location, I'm still new to all of this.&lt;/P&gt;
&lt;P&gt;Anyway, we have a subscription to MaxMind databases (Connection-Type, Domain, and ISP databases) and I would like to implement them, but don't know how. &amp;nbsp;I don't know where to store the DB's, how to link them together (if they need to be linked), and how to add them so that I utilize them in searches.&lt;/P&gt;
&lt;P&gt;I'm fairly new to Splunk, so feel free to treat me like someone who doesn't know anything.&lt;/P&gt;
&lt;P&gt;Greatly appreciate your help with this!&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 17:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536042#M151544</guid>
      <dc:creator>frog22</dc:creator>
      <dc:date>2022-05-17T17:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: MaxMind DB Usage (more than just City)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536064#M151558</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Iplocation" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Iplocation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;check &lt;STRONG&gt;Updating the MMDB file&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 22:01:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536064#M151558</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-15T22:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: MaxMind DB Usage (more than just City)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536100#M151572</link>
      <description>&lt;P&gt;to4kawa, while I appreciate the assistance that is already information I have. &amp;nbsp;I'm able to replace/update the Geolocation data, but there are 3 other databases worth of information that are not Geolocation data. &amp;nbsp;Since they are, collectively, 4 independent databases I'm trying to figure out how to implement them in Splunk as I believe the other 3 require the ID field in the City database in order to correlate information within the individual databases.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 04:00:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536100#M151572</guid>
      <dc:creator>frog22</dc:creator>
      <dc:date>2021-01-16T04:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: MaxMind DB Usage (more than just City)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536102#M151573</link>
      <description>&lt;P&gt;I've never done that before.&lt;BR /&gt;It seems to be provided as a CSV file, so why don't you register it as a lookup?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 04:16:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536102#M151573</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-16T04:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: MaxMind DB Usage (more than just City)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536767#M151751</link>
      <description>&lt;P&gt;to4kawa,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lookups may be a possibility, but it's beyond my skill level and it adds layers of complication to the maintenance....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Updates come out weekly&lt;/P&gt;&lt;P&gt;2. There are 2 csv files per 1 mmdb file (6 csv files, 3 mmdb files), which will require a total of 6 lookups to maintain and run queries against&lt;/P&gt;&lt;P&gt;3. The csv files / mmdb's utilize subnet ranges (IPV4 &amp;amp; IPV6 address ranges).....1.0.64.0/24, 78.129.0.0/17, 185.91.188.0/22, 2001:218:3000::/46, 2001:410:80::/37, 2a00:df0::/32, 2a04:f580:9240::/48&lt;/P&gt;&lt;P&gt;4. The csv files utilize both IPV4 and IPV6 addresses&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm totally open to suggestions, though. &amp;nbsp;Thanks!!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 00:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/536767#M151751</guid>
      <dc:creator>frog22</dc:creator>
      <dc:date>2021-01-22T00:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: MaxMind DB Usage (more than just City)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/598066#M208262</link>
      <description>&lt;P&gt;did you find a solution for this?&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 10:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/598066#M208262</guid>
      <dc:creator>jnhth</dc:creator>
      <dc:date>2022-05-17T10:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: MaxMind DB Usage (more than just City)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/622318#M216324</link>
      <description>&lt;P&gt;In Splunk Cloud, CSVs are one way to go.&amp;nbsp;&amp;nbsp; We did this with the free ASN DB when we moved to cloud (couldn't get &lt;A href="https://splunkbase.splunk.com/app/3531" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3531&lt;/A&gt; for cloud).&amp;nbsp;&lt;/P&gt;&lt;P&gt;In short,&amp;nbsp; it's a CSV-backed lookup with a CIDR match type over the column/field with the network range.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We're also looking at &lt;A href="https://splunkbase.splunk.com/app/3022" target="_blank"&gt;https://splunkbase.splunk.com/app/3022&lt;/A&gt; now.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 21:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/MaxMind-DB-Usage-more-than-just-City-How-to-store-and-link-DBs/m-p/622318#M216324</guid>
      <dc:creator>hughkelley</dc:creator>
      <dc:date>2022-11-28T21:55:45Z</dc:date>
    </item>
  </channel>
</rss>

