I want to build my own python code that gets parameter IP address, My script using IP2Location and return information about the IP address with IP2Location DB IP2Location https://www.ip2location.com/developers
So what I did is build my python script that receives IP address and returns CSV row with the result of IP2Location.
My script is located in: /opt/splunk/etc/apps/search/bin
external_cmd = ip2location.py clientip
fields_list = What shold I write here?
I'm trying to understand:
1. How do I need to configure the section on [ip2location] in transform.conf?
2. What is the meaning of fields_list?
3. How can I make my script to work in Splunk? I just want Splunk to give my script IP address and return csv as result.