Yeah, use the Splunk 6 iplocation
command: http://docs.splunk.com/Documentation/Splunk/6.1.2/SearchReference/iplocation
That adds a Country
field amongst other things.
As of Splunk 6, you can use the iplocation command:
http://docs.splunk.com/Documentation/Splunk/6.1.2/SearchReference/Iplocation
This will provide the extra fields that you can use to get the stats you want. for example:
index=firewall | iplocation src_ip | stats count by City Country