Splunk Search

Maxmind GeoIP2 updates in a Clustered Environment

Ovi
Path Finder

I have a multisite indexer cluster with one SH
I configured automated GeoIP2-City Maxmind DB (paid subscription) downloads that refresh this DB on the SH every week
I am also using Data Models across multiple applications that that include calculated Country, City etc. fields and make use of this GeoIP database

Questions:
For a clustered environment such as this and using Data Models - should I push the DB updates to the Indexers as well to avoid any inconsistency in the search results?
Does Splunk needs to be restarted or debug/refresh to pick up the DB change
Any other guidance on this setup in a clustered environment
Thanks

Tags (2)

ifotopoulos
Explorer

You should do it on both (SH and indexers) otherwise you are going to have discrepancies. Iplocation is a streaming command and depending on your search it can either be applied at the indexers level or at the SH level.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...