<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google maps finds a specific IP in multiple areas in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171817#M49243</link>
    <description>&lt;P&gt;If you want to filter by clientip then you can do that before the first pipe.&lt;/P&gt;

&lt;P&gt;As for upgrading to 6, that's easy as can be. Just do an upgrade install, no need to uninstall first. Always keep an up-to-date backup of course &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2013 11:12:44 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2013-12-09T11:12:44Z</dc:date>
    <item>
      <title>Google maps finds a specific IP in multiple areas</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171814#M49240</link>
      <description>&lt;P&gt;Hello Splunk users,&lt;/P&gt;

&lt;P&gt;It is not a long time since I started using Splunk. I have Google Maps API installed and I am trying to locate the location of IPs in my logs.&lt;BR /&gt;
As an example of the queries I apply I give you the following 2:&lt;/P&gt;

&lt;P&gt;1) &lt;STRONG&gt;sourcetype=LogEvents | geoip clientip=12.34.56.78&lt;/STRONG&gt;&lt;BR /&gt;
Above query returns me thousands of logs. However, with the specific IP there is only 1 (one) log in reality. Last, even though it returns me so much logs, in the map there are &lt;STRONG&gt;only&lt;/STRONG&gt; about 20 dots with location.&lt;/P&gt;

&lt;P&gt;2) &lt;STRONG&gt;sourcetype=LogEvents &lt;EM&gt;remote access&lt;/EM&gt; &lt;EM&gt;failed&lt;/EM&gt; | geoip clientip=12.34.56.78&lt;/STRONG&gt;&lt;BR /&gt;
Above query works fine in terms that it returns me the correct number of failed logs. The thing is however, that again not all returned logs belong to that IP address. Are only the "failed" logs as defined by the query.&lt;/P&gt;

&lt;P&gt;Any, any thoughts, are greatly appreciated!&lt;BR /&gt;
Best regards,&lt;BR /&gt;
Evangelos&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 10:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171814#M49240</guid>
      <dc:creator>evang_26</dc:creator>
      <dc:date>2013-12-09T10:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Google maps finds a specific IP in multiple areas</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171815#M49241</link>
      <description>&lt;P&gt;What are you trying to achieve by specifying a concrete IP when calling geoip?&lt;/P&gt;

&lt;P&gt;Also, you should take a look at Splunk 6 - that comes with a built-in iplocation command.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171815#M49241</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-12-09T11:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Google maps finds a specific IP in multiple areas</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171816#M49242</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;

&lt;P&gt;Thanks commenting this out. What I am trying to do is to find the location from where a specific IP created a log. &lt;/P&gt;

&lt;P&gt;I currently have installed v5.0.2. I think it would be quite difficult to unistall and install from the scratch at 6 version. &lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Evangelos&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171816#M49242</guid>
      <dc:creator>evang_26</dc:creator>
      <dc:date>2013-12-09T11:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Google maps finds a specific IP in multiple areas</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171817#M49243</link>
      <description>&lt;P&gt;If you want to filter by clientip then you can do that before the first pipe.&lt;/P&gt;

&lt;P&gt;As for upgrading to 6, that's easy as can be. Just do an upgrade install, no need to uninstall first. Always keep an up-to-date backup of course &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171817#M49243</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-12-09T11:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Google maps finds a specific IP in multiple areas</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171818#M49244</link>
      <description>&lt;P&gt;Okay, that seems to be working as for now, part of it at least.&lt;BR /&gt;
What I did is this: sourcetype=LogEvents remote access failed 12.34.56.78 | geoip&lt;/P&gt;

&lt;P&gt;It now returns the correct number of logs, but not in the exact location, only country. Is this how it works?&lt;/P&gt;

&lt;P&gt;I am considering the upgraide, but I am defering for now because I am newbie.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171818#M49244</guid>
      <dc:creator>evang_26</dc:creator>
      <dc:date>2013-12-09T11:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Google maps finds a specific IP in multiple areas</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171819#M49245</link>
      <description>&lt;P&gt;Precision varies, resolving IP to location is not an exact science.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Google-maps-finds-a-specific-IP-in-multiple-areas/m-p/171819#M49245</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-12-09T11:37:39Z</dc:date>
    </item>
  </channel>
</rss>

