Having some trouble getting the GeoASN app working in my lab environment
I followed the instructions to compile and copy the C SDK, Python SDK to my search head
testing via command line seems to work
[root@spweb2-s1-inf bin]# /app/splunk/bin/splunk cmd python ga.py < ga.csv ip,country,asn,org 126.96.36.199,Brazil,27699,DE SAO PAULO S/A - TELESP 188.8.131.52,Japan,10000,Nagasaki Cable Media Inc. 192.168.10.10,RFC1918,0,RFC1918 10.10.20.20,RFC1918,0,RFC1918 184.108.40.206,Unknown,0,Unknown 172.19.20.21,RFC1918,0,RFC1918 220.127.116.11,Unknown,0,Unknown 172.31.1.1,RFC1918,0,RFC1918 18.104.22.168,Unknown,0,Unknown
However testing in the ui does not populate the country, asn fields etc
sourcetype="access_combined" | lookup ga ip
Lookup file and app permissions are all set to global read/write but no change with the new fields populating.