Splunk Search

In Splunk 6.2.3, what happened to the CountryCode field that was part of the output from using the iplocation command in Splunk 6.0.1?

jedatt01
Builder

I set up a search on Splunk 6.0.1 that used the IPlocation command. In the output, I got field called CountryCode that contained a two letter country code associated with the Country. I've now upgraded to 6.2.3 and I no longer see CountryCode as part of the output when I run iplocation. What happened to CountryCode?

0 Karma
1 Solution

bawood
Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

View solution in original post

bawood
Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

jedatt01
Builder

bawood is correct! It works to use lang=code.

franks59
Explorer

I believe that is now _country_code

0 Karma

cmlombardo
Path Finder

franks59 that field does not exist.

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...