My iplocation is not working at all, what am i missing?
index=_internal sourcetype=splunkd_ui_access | stats count by clientip | iplocation clientip
I don't get any city or country at all.
I am on Splunk Version:7.1.6 [Dec 2018], these are the files i currently have in the directory.
Do i need to update them to get this to work, or should something work by default?
There are only private IP addresses in your screenshot, no public ones. There is no location lookup for private IP addresses.
The iplookup command itself works, otherwise you wouldn't get the columns for City and Country. It is just not possible to determine these for private IPs.