We have a subscription for MaxMind and I am trying to figure out how to use the ISP and Organization fields from the database. Can iplocation be extended for new fields, or do I have to build an TA?
Thanks!
Have you tried the apps?
https://splunkbase.splunk.com/apps/?search=Maximimd#/order/relevance/search/Maxmind
Working on the SecKit App which appears to be broken out of the box, but a good starting point. I am close to having it working. I was hoping that the iplocation command could be extended. Thanks!
If it works out, click "Accept" to close the question.