Knowledge Management

Can you show me how to setup IP GEO lookup workflow action

thakarpratik
Engager

Hi guys, i am learning splunk , and working my way through Workflow action, i have a dataset which has a clientip field with over 100+ unique IP address

I am trying to get their GEO location of each IP, can i do that via Workflow action? or i have to do it via LOOKUP?

Can you please show me how to do it?

Tags (2)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Assuming the IP addresses are all internet routable and not private addresses this should work fine:

... | iplocation clientip | geostats count by Country

If you want additional fields that iplocation doesnt provide, you can dig into some geospatial lookups:

https://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Configuregeospatiallookups

thakarpratik
Engager

So I achieve this using LOOKUP or via workflow action?

0 Karma

woodcock
Esteemed Legend

Attach the given string to the end of your existing search. That is it.

Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...