Deployment Architecture

Do I need to update the 'GeoLite2-City' database on the search head cluster AND index cluster?


I have an IP ( that I'm trying to geolocate, but the City and Region fields are returning as Null. When I geolocate using the Maxmind 'GeoIP2 City Database Demo', I get all the values I expect.

In reading the documentation for the iplocation command I came across the instructions for updating the database. But the instructions aren't quite clear if I need to update the database on the SH cluster or the Index cluster (or both). There is a paragraph stating that you /can/ update on the indexer, but to me this is different than saying you /must/. What are the steps to update the geoip database in a distributed cluster? I actually did it on both but this did not change my results, so I must be doing it wrong.

0 Karma


You should do it on both otherwise you are going to have discrepancies. Iplocation is a streaming command and depending on your search it can either be applied at the indexers level or at the SH level.

0 Karma


You should only need to do so at the search layer. This is how I do it on standalone search heads:

In a search cluster, you would probably want to keep the SH deployer file up to date, and schedule a push to the members once a month. I'm not sure the way you're doing it today, but if you're not updating the lookup through the GUI or SH Deployer, it's probably not getting propagated to the other members.

0 Karma


I actually opened a support case on this. I did not get the sense that the engineer was really committed to answering my question, but this is the response I got:

I would suggest you do it on your indexer. Currently, the iplocation command in a distributed environment runs on the peers. When a paid or custom .mmdb file is used, it has to be changed on each peer. You can use localop to force it to the SH, but there's no way to do it automatically. All of the search peers will need it, as unless you have localop, the iplocation will be done on the search peer.

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...