- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can use the iplocation
search command to manually add location information based on IPv4 address in a search:
sourcetype=access_combined | iplocation clientip
In order to drive maps in dashboards with that information it's recommended to use the geostats
command, which precomputes aggregated information for multiple zoom levels:
sourcetype=access_combined | iplocation clientip | geostats count
or
sourcetype=access_combined | iplocation clientip | geostats count by method
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can use the iplocation
search command to manually add location information based on IPv4 address in a search:
sourcetype=access_combined | iplocation clientip
In order to drive maps in dashboards with that information it's recommended to use the geostats
command, which precomputes aggregated information for multiple zoom levels:
sourcetype=access_combined | iplocation clientip | geostats count
or
sourcetype=access_combined | iplocation clientip | geostats count by method
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

ChrisG: Thanks for pointing this out, but I was more asking for another IPv4 to location translation data base.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


I think you can point to any tile server using the mapping.tileLayer.url attribute of the
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hey zigi, thanks. Fast and precise as always 🙂
Whichgeoip ddatabase is shipped with Splunk by default? Is there a way to replace it, eg. with a commercial version of maxmind?
