All Apps and Add-ons

how to update the maxmind db in Geo Location lookup script?

peasead
Path Finder

Again, very good app.

How can we update the database? I assume ~/bin/GeoLiteCity.dat is what needs to be updated? What needs to be downloaded from MAXMIND and put where?

sonicZ
Contributor

I believe you can update the existing GeoLiteCity.dat with the files available from maxmind
http://www.maxmind.com/en/geolite
unzip the latest binary in the directory with the existing .dat file.

I am using the GeoASN app and the files reside in a different location.

> [root@splunksearch1-d1-inf apps]# ls
> -l /app/splunk/etc/apps/GeoASN/lookups/
> total 84460
> -rw-rw-r-- 1 root   root    3872281 Apr  2  2011 GeoIPASNum.dat
> -rw-r--r-- 1 splunk splunk 54878292 Jun 15  2012 GeoLiteCity.dat
> -rw-rw-r-- 1 root   root   27629545 Apr  4  2011 GeoLiteCity.old
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...