All Apps and Add-ons

Can iplocation be extended for new fields to use the ISP and Organization fields from a commercial MaxMind database?

ebailey
Communicator

We have a subscription for MaxMind and I am trying to figure out how to use the ISP and Organization fields from the database. Can iplocation be extended for new fields, or do I have to build an TA?

Thanks!

woodcock
Esteemed Legend
0 Karma

ebailey
Communicator

Working on the SecKit App which appears to be broken out of the box, but a good starting point. I am close to having it working. I was hoping that the iplocation command could be extended. Thanks!

woodcock
Esteemed Legend

If it works out, click "Accept" to close the question.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...