Splunk Search

Is it possible to do GeoIP of private IPaddresses?

rosho
Communicator

Hi

I am a user of Splunk and Elasticsearch.
I want to do GeoIP with private IPaddresses. There is information about it on the Elasticsearch forum (ex: Private networks with GeoIP This confirms that it is possible with Elasticsearch. But what about Splunk?

Thank you

0 Karma
1 Solution

starcher
Influencer

If you maintain an asset list of IP ranges to lat/long you could put it into a lookup and use that.

View solution in original post

starcher
Influencer

If you maintain an asset list of IP ranges to lat/long you could put it into a lookup and use that.

rosho
Communicator

Can you give me an example of how does the lookup would look like?

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...