Splunk Search

How to enable iplocation

mbohlsen
Engager

How do I "enable" iplocation in Splunk Ent. 6.2.2. I thought it might be just an automatic function now that the database is default. When I try searches using "iplocation" context it brings up nothing. Any help would be greatly appreciated as I can find details on this anywhere.
Note, I have a cluster environment with two peers and another server acting as the master/search head. Thanks in advance.

0 Karma

chaker
Contributor

Hi,

IP location works well.

Are you using the command against public IP's?

Post a sample search that's not working.

http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Iplocation

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...