Splunk Enterprise

Are there addons for Splunk geolocating devices?

jip31
Motivator

Hello

I have basic questions about hte way to geolocate devices with Splunk

Is an addon exists?

If not, is it possible to correlate a tool like NetDB with Splunk using DB Connect?

https://web.stanford.edu/group/networking/netdb/help/prod/netdb.html

If yes, what are the prerequesites for doing this?

Thanks

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't see an app on splunkbase, but that doesn't mean you can't use the NetDB API to create one.

If there's a JDBC driver for NetDB then you may be able to use DB Connect.

---
If this reply helps you, Karma would be appreciated.
0 Karma

andrew_nelson
Path Finder

For public IP address space, Splunk comes with an | iplocation function with data accurate as of the Splunk package being published.
iplocation - Splunk Documentation

The documentation comes with info on how to update the database. 

0 Karma

jip31
Motivator

OK but it will do no work for me because it's not public adress but internal adress

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...