Splunk Search

Is there a way to enrich events by having country information from IP address automatically through props.conf?

efheem
Explorer

Hello,

I am trying to come-up with something which will automatically enrich the events using the country information using the src_ip field in the events. I understand that the iplocation command can do this in search time. Is there any way we can get this done automatically using props.conf? I am expecting to have a lookup file which we can leverage to achieve this and I cannot find any.

Cheers.

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...