I have events in Splunk that contain GPS data -- longitude and latitude, and I can plot these on a map using either the built in Splunk maps support, or the Google maps app. What I'd really like though is to be able to filter events on e.g. country=US. Does anyone know of a way to calculate a country attribute based on GPS coordinates?
Thanks!
Hi MatMeredith,
Have you met http://dev.maxmind.com/geoip/legacy/codes/country_latlon/ yet?
You can use this as lookup, either manual or automatic.
hope this helps to get you started ...
cheers, MuS