Splunk Search

In Splunk 6.2.3, what happened to the CountryCode field that was part of the output from using the iplocation command in Splunk 6.0.1?

Builder

I set up a search on Splunk 6.0.1 that used the IPlocation command. In the output, I got field called CountryCode that contained a two letter country code associated with the Country. I've now upgraded to 6.2.3 and I no longer see CountryCode as part of the output when I run iplocation. What happened to CountryCode?

0 Karma
1 Solution

Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

View solution in original post

Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

View solution in original post

Builder

bawood is correct! It works to use lang=code.

Explorer

I believe that is now countrycode

0 Karma

Path Finder

franks59 that field does not exist.

0 Karma