Splunk Enterprise Security

Spontaneous "Health Check" error messages reported on ES Search Head regardng "maxmind_geoip_asn_ipv6" failed download?

woodcock
Esteemed Legend

We are getting the following errors on our Enterprise Security Search Head and are wondering why and how to fix them:

Health Check: Intelligence download of "maxmind_geoip_asn_ipv6" has failed on host "ES_Search_Head_Host" at: Sat Apr 27 20:45:45 2019 "threat list download failed after multiple retries"  Learn more.
4/27/2019, 9:00:31 PM
Health Check: Intelligence download of "maxmind_geoip_asn_ipv4" has failed on host "ES_Search_Head_Host" at: Sat Apr 27 20:45:45 2019 "threat list download failed after multiple retries"  Learn more.
4/27/2019, 9:00:31 PM

If I have to, I will dig into it and figure it out and followup here, but I am hoping that somebody has already figured it out.

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Just installed ES 5.3.0 and the old URL is still used, but it is disabled. Here is the new URL https://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN-CSV.zip to download the file.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Just installed ES 5.3.0 and the old URL is still used, but it is disabled. Here is the new URL https://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN-CSV.zip to download the file.

cheers, MuS

alexeyglukhov
Path Finder

Just wanted to provide an update in case someone faced the issue.

Latest URL looks like this:

https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-ASN-CSV&license_key=YOUR_LICENSE_KEY_HERE&suffix=zip

License key you can generate in your profile when you register on maxmind website.

0 Karma

MuS
SplunkTrust
SplunkTrust

The download works fine using http or https, to me it looks the post processing of the files fails in ES. For now I just use a work around and download the file by cronjob, put the csv into the lookup folder and use the lookup:// URL in ES.

cheers, MuS

0 Karma

spectrum2035
Explorer

@MuS - whether it is downloading with the new link? I am still getting the same error

0 Karma

woodcock
Esteemed Legend

Go to Enterprise Security -> Configure -> Data Enrichment -> Intelligence Downloads and search for maxmind. You will see 2 entries and these have the following URLs:

https://download.maxmind.com/download/geoip/database/asnum/GeoIPASNum2.zip
https://download.maxmind.com/download/geoip/database/asnum/GeoIPASNum2v6.zip

As expected, these URLs are no longer valid. I found this link with more details:
https://support.maxmind.com/geolite-legacy-discontinuation-notice/

I am on ES v5.1.0 which is not the latest and I assume that the later versions have already accommodated this discontinuation. For now, until I upgrade, I have just disabled these 2 feeds, since we are not using them anyway.

woodcock
Esteemed Legend

@ppablo_splunk You should unaccept my answer and accept the one from @MuS.

ppablo
Retired

Thanks @woodcock !

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...