Splunk Search

How does iplocation identify anonymous proxies?

bdenes_snap
Engager

We use IpLocation at my company and its performing pretty well. I would like to find out a bit more of how the IpLocation plug-in identifies anonymous proxies - our business is trying to make a decision if we can rely on this to filter out spammers.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If your ip field contains a proxy IP then the iplocation command will treat it as any other IP - look up its location. The database backing this doesn't have any knowledge of whether an IP is running a proxy or not.

You may want to look into the IP Reputation app: http://apps.splunk.com/app/1457/
Using data from Project Honeypot that flags known abusive IPs with a focus on spam.

0 Karma

bdenes_snap
Engager

Thank you - but let me update my question. If the ip field is a proxy in the search results we see "Anonymous Proxy". This is impressive, because from what we can tell, it is better then Vindicia's proxy detection or any other paid service's. I'll try to upload a screen shot in a bit...

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...