Splunk Search

How does iplocation identify anonymous proxies?

bdenes_snap
Engager

We use IpLocation at my company and its performing pretty well. I would like to find out a bit more of how the IpLocation plug-in identifies anonymous proxies - our business is trying to make a decision if we can rely on this to filter out spammers.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If your ip field contains a proxy IP then the iplocation command will treat it as any other IP - look up its location. The database backing this doesn't have any knowledge of whether an IP is running a proxy or not.

You may want to look into the IP Reputation app: http://apps.splunk.com/app/1457/
Using data from Project Honeypot that flags known abusive IPs with a focus on spam.

0 Karma

bdenes_snap
Engager

Thank you - but let me update my question. If the ip field is a proxy in the search results we see "Anonymous Proxy". This is impressive, because from what we can tell, it is better then Vindicia's proxy detection or any other paid service's. I'll try to upload a screen shot in a bit...

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...