All Apps and Add-ons

Splunk GeoIP database

darioapis
Explorer

I have one simple question. Does Splunk use paid "GeoLite2-City.mmdb" version or free one. The reason is that, if it is not paid then I can upgrade it manually. Thanks.

0 Karma
1 Solution

chrisyounger
SplunkTrust
SplunkTrust

Hi @darioapis

Its not paid, so you can update it if you like. There are also Splunkbase apps that can do it for you. Like this one: https://splunkbase.splunk.com/app/4183/

All the best

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

This App seems to be really useful - https://splunkbase.splunk.com/app/5482/.

The App auto-updates the MaxMind database without going into the backend every week. It also allows you to run a search command on Splunk search to manually download and update the latest database.

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @darioapis

Its not paid, so you can update it if you like. There are also Splunkbase apps that can do it for you. Like this one: https://splunkbase.splunk.com/app/4183/

All the best

_joe
Communicator

It appears the automatic update portion only works if you have a paid API key. 

0 Karma

markhill1
Path Finder

Hi, Actually it works with just the free sign-up, I have been using it that way for a long time now. Unless you are talking about the auto-update app they have for installing on your host machine. I haven't used that before. Thanks.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...