Splunk Dev

How does GeoLite2-City.mmdb Update in Splunk

splunkrocks2014
Communicator

Hi. "/opt/splunk/share/GeoLite2-City.mmdb" is used by iplocation command; however, this file is outdated. I can manually download the file from here, but does Splunk have a built-in function can be used to update the database file automatically? Thanks.

Tags (1)
0 Karma

starcher
Influencer

yannK
Splunk Employee
Splunk Employee

No there is not automatic update method.
Usually the database get's updated when you upgrade splunk with the version that is shipped with it.

You can manually upgrade the database if you have a more recent copy, or have a paid version of the database.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...