Knowledge Management

Can you show me how to setup IP GEO lookup workflow action

thakarpratik
Engager

Hi guys, i am learning splunk , and working my way through Workflow action, i have a dataset which has a clientip field with over 100+ unique IP address

I am trying to get their GEO location of each IP, can i do that via Workflow action? or i have to do it via LOOKUP?

Can you please show me how to do it?

Tags (2)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Assuming the IP addresses are all internet routable and not private addresses this should work fine:

... | iplocation clientip | geostats count by Country

If you want additional fields that iplocation doesnt provide, you can dig into some geospatial lookups:

https://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Configuregeospatiallookups

thakarpratik
Engager

So I achieve this using LOOKUP or via workflow action?

0 Karma

woodcock
Esteemed Legend

Attach the given string to the end of your existing search. That is it.

Get Updates on the Splunk Community!

App Building 101 - Build Your First App!

WATCH RECORDING NOW   Tech Talk: App Dev Edition Splunk has tons of out-of-the-box functionality, and you’ve ...

Introducing support for Amazon Data Firehose in Splunk Edge Processor

We’re excited to announce a powerful update to Splunk Data Management with added support for Amazon Data ...

The Observability Round-Up: September 2024

What’s up Splunk Community! Welcome to the latest edition of the Observability Round-Up, a monthly series in ...