All Apps and Add-ons

how to update the maxmind db in Geo Location lookup script?

peasead
Path Finder

Again, very good app.

How can we update the database? I assume ~/bin/GeoLiteCity.dat is what needs to be updated? What needs to be downloaded from MAXMIND and put where?

sonicZ
Contributor

I believe you can update the existing GeoLiteCity.dat with the files available from maxmind
http://www.maxmind.com/en/geolite
unzip the latest binary in the directory with the existing .dat file.

I am using the GeoASN app and the files reside in a different location.

> [root@splunksearch1-d1-inf apps]# ls
> -l /app/splunk/etc/apps/GeoASN/lookups/
> total 84460
> -rw-rw-r-- 1 root   root    3872281 Apr  2  2011 GeoIPASNum.dat
> -rw-r--r-- 1 splunk splunk 54878292 Jun 15  2012 GeoLiteCity.dat
> -rw-rw-r-- 1 root   root   27629545 Apr  4  2011 GeoLiteCity.old
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...