hi, i bought two geoip database from maxmind.
Geoip city and Gepip isp, how to use two?
thankyou
anyone could be kind enough to do me a favor and combine geocity and geo isp in one app ?
Thank you!
you will either need :
-to modify the splunk/etc/apps/MAXMIND/bin/geoip.py
or
-duplicate the apps and change his name(folder and splunk/etc/apps/MAXMIND/default/app.conf
) and search command in splunk/etc/apps/MAXMIND/default/transforms.conf
.