Getting Data In

iplocation command not working



I am using splunk enterprise 6.0 and i used iplocation command on a index using the following command and it just returned the results fine.

index=idx1 sourcetype=access_combined ....| iplocation prefix=iploc_ allfields=true clientip

Now I am using the same command on different index and different sourcetype its not working.

index=idx2 sourcetype="access_*" .... | iplocation clientip

There are no interesting fields column in the search results page?? Any idea why is this happening.

0 Karma


Splunk 6.1 has changed the iplocation a bit.

.... | iplocation clientip | stats count by Country, Region

works natively now 🙂