- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ptur
Path Finder
10-12-2017
09:28 AM
Simply put i index a logon log to one of our services. I would like to create a table that would show me results based on geolocation, i.e. in this case, all connections made from IP addresses outside of north america. Is this possible on Splunk Cloud?
Thanks!
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

mgast
Explorer
10-12-2017
10:03 AM
sourcetype=access_* status>=400 | head 20 | iplocation clientip | table clientip, status, City, Country|where Country !="United States"
Splunk has a builtin iplocation that works great.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

mgast
Explorer
10-12-2017
10:03 AM
sourcetype=access_* status>=400 | head 20 | iplocation clientip | table clientip, status, City, Country|where Country !="United States"
Splunk has a builtin iplocation that works great.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ptur
Path Finder
10-12-2017
11:00 AM
thanks! looks great
