Splunk Search

In Splunk 6.2.3, what happened to the CountryCode field that was part of the output from using the iplocation command in Splunk 6.0.1?

jedatt01
Builder

I set up a search on Splunk 6.0.1 that used the IPlocation command. In the output, I got field called CountryCode that contained a two letter country code associated with the Country. I've now upgraded to 6.2.3 and I no longer see CountryCode as part of the output when I run iplocation. What happened to CountryCode?

0 Karma
1 Solution

bawood
Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

View solution in original post

bawood
Path Finder

I think the way to do this now is to set the option lang=code. That turns the Country field into the 2 char abbreviation and at least for US, the states abbreviation.

jedatt01
Builder

bawood is correct! It works to use lang=code.

franks59
Explorer

I believe that is now _country_code

0 Karma

cmlombardo
Path Finder

franks59 that field does not exist.

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...