I have one simple question. Does Splunk use paid "GeoLite2-City.mmdb" version or free one. The reason is that, if it is not paid then I can upgrade it manually. Thanks.
Hi @darioapis
Its not paid, so you can update it if you like. There are also Splunkbase apps that can do it for you. Like this one: https://splunkbase.splunk.com/app/4183/
All the best
This App seems to be really useful - https://splunkbase.splunk.com/app/5482/.
The App auto-updates the MaxMind database without going into the backend every week. It also allows you to run a search command on Splunk search to manually download and update the latest database.
Hi @darioapis
Its not paid, so you can update it if you like. There are also Splunkbase apps that can do it for you. Like this one: https://splunkbase.splunk.com/app/4183/
All the best
It appears the automatic update portion only works if you have a paid API key.
Hi, Actually it works with just the free sign-up, I have been using it that way for a long time now. Unless you are talking about the auto-update app they have for installing on your host machine. I haven't used that before. Thanks.