Splunk Search

How to use iplocation to search for instances of a specific city or region?

mgp173455
Loves-to-Learn

Hello, 

I am trying to use iplocation to search for instances of a specific city or region for example: 

* iplocation ipaddress Region="region" 

Instead of returning that specific region it will return all regions. Can anyone tell me if this is a bug or am I missing something? 

Thanks 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The iplocation command does not have a region option.

iplocation [prefix=<string>] [allfields=<bool>] [lang=<string>] <ip-address-fieldname>

See https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Iplocation 

---
If this reply helps you, Karma would be appreciated.
0 Karma

mgp173455
Loves-to-Learn

2DA9842C-92D5-4E27-B93D-4E3BD694D3B9.png

Hi thank you for your reply! 

Ahh I see. From my understanding  the documentation displays a region field with a prefix iploc_ to help distinguish from other fields that might already be present with the same name. 

In my case I don’t have a previous region field so I don’t use the prefix query. Could you provide more insight as to why a prefixed field might be displayed if not supported? (i.e. I have tried doing this with iploc_Region as well) 

 

Any help is much appreciated!

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Region/iploc_region are *output* fields, not input fields. They're part of the results, not part of the command.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...