Splunk Dev

How does GeoLite2-City.mmdb Update in Splunk

splunkrocks2014
Communicator

Hi. "/opt/splunk/share/GeoLite2-City.mmdb" is used by iplocation command; however, this file is outdated. I can manually download the file from here, but does Splunk have a built-in function can be used to update the database file automatically? Thanks.

Tags (1)
0 Karma

starcher
Influencer

yannK
Splunk Employee
Splunk Employee

No there is not automatic update method.
Usually the database get's updated when you upgrade splunk with the version that is shipped with it.

You can manually upgrade the database if you have a more recent copy, or have a paid version of the database.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...