Splunk Search

How to enable iplocation


How do I "enable" iplocation in Splunk Ent. 6.2.2. I thought it might be just an automatic function now that the database is default. When I try searches using "iplocation" context it brings up nothing. Any help would be greatly appreciated as I can find details on this anywhere.
Note, I have a cluster environment with two peers and another server acting as the master/search head. Thanks in advance.

0 Karma

Re: How to enable iplocation

Path Finder


IP location works well.

Are you using the command against public IP's?

Post a sample search that's not working.


0 Karma