Getting Data In

iplocation command not working

krish3
Contributor

Hi,

I am using splunk enterprise 6.0 and i used iplocation command on a index using the following command and it just returned the results fine.

index=idx1 sourcetype=access_combined ....| iplocation prefix=iploc_ allfields=true clientip

Now I am using the same command on different index and different sourcetype its not working.

index=idx2 sourcetype="access_*" .... | iplocation clientip

There are no interesting fields column in the search results page?? Any idea why is this happening.
Thanks,

0 Karma

hagjos43
Contributor

Splunk 6.1 has changed the iplocation a bit.

.... | iplocation clientip | stats count by Country, Region

works natively now 🙂

Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...