Dashboards & Visualizations

How reliable is the location value produced by the "iplocation" command?

yossefn
Path Finder

Hi, 

I need to create a report the will summary the countries that our users connected our network from.

Using the "iplocation" command I got a results, but for sure I can say that I know about an employee connected from a country in Europe but in the logs it appears that he connected from a country in the middle east.

Is there more accurate option to make sure I will present the correct information?

Thanks.  

Tags (1)
0 Karma

yossefn
Path Finder

Thank you @gcusello 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @yossefn,

the problem isn't how much accurate is the option, it depends on the table used to correlate IP addresses and coordinates (lat and long).

If you want there are some more datailed tables than the ones in Splunk (paying!).

Anyway the problem probably isn't in the table but in the location of the Internet accesses of your organization: maybe a paople is in a site (Middle East) but the access point in in another site (Europe). 

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...