Splunk Search

How to enable iplocation

mbohlsen
Engager

How do I "enable" iplocation in Splunk Ent. 6.2.2. I thought it might be just an automatic function now that the database is default. When I try searches using "iplocation" context it brings up nothing. Any help would be greatly appreciated as I can find details on this anywhere.
Note, I have a cluster environment with two peers and another server acting as the master/search head. Thanks in advance.

0 Karma

chaker
Contributor

Hi,

IP location works well.

Are you using the command against public IP's?

Post a sample search that's not working.

http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Iplocation

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...