I am using splunk enterprise 6.0 and i used iplocation command on a index using the following command and it just returned the results fine.
index=idx1 sourcetype=access_combined ....| iplocation prefix=iploc_ allfields=true clientip
Now I am using the same command on different index and different sourcetype its not working.
index=idx2 sourcetype="access_*" .... | iplocation clientip
There are no interesting fields column in the search results page?? Any idea why is this happening.
Splunk 6.1 has changed the iplocation a bit.
.... | iplocation clientip | stats count by Country, Region
works natively now 🙂