Splunk Search

How does iplocation identify anonymous proxies?

Engager

We use IpLocation at my company and its performing pretty well. I would like to find out a bit more of how the IpLocation plug-in identifies anonymous proxies - our business is trying to make a decision if we can rely on this to filter out spammers.

Tags (2)
0 Karma

SplunkTrust
SplunkTrust

If your ip field contains a proxy IP then the iplocation command will treat it as any other IP - look up its location. The database backing this doesn't have any knowledge of whether an IP is running a proxy or not.

You may want to look into the IP Reputation app: http://apps.splunk.com/app/1457/
Using data from Project Honeypot that flags known abusive IPs with a focus on spam.

0 Karma

Engager

Thank you - but let me update my question. If the ip field is a proxy in the search results we see "Anonymous Proxy". This is impressive, because from what we can tell, it is better then Vindicia's proxy detection or any other paid service's. I'll try to upload a screen shot in a bit...

0 Karma