The database used by iplocation is updated usually with each new version of Splunk. What is the best solution to preserve the changes? For example a particular IP address might have had a different geolocation last year then it has now.
if you use a customised path for your iplocation DB using limits.conf
db_path = <path>
* Absolute path to GeoIP database in MMDB format
* If not set, defaults to database included with splunk
it will not get updated by any Splunk version update.
Hope this helps ...
View solution in original post
Thanks, that solution will preserve the old values, but for new events it would be preferable to use the latest database. Something like we have with the time based lookups in Splunk.
Well, in this case it would be best for you to create your own lookup table based no your requirements, because this can only be handled by yourself, based on your requirements.