Splunk Search

iplocation draws blank

Communicator

This doesn't returns anything:
| stats c | eval ip="107.181.233.178" | iplocation ip allfields=1 | table ip, Country, Region, City
likely due to iplocation's usage of limited geoip DB?

Is there a way (perhaps for an extra fee?) to plug into Splunk more robust and rich IP location and assignment resolution capabilities?

Tags (1)
0 Karma

SplunkTrust
SplunkTrust

You should reference this already answered question which will be what you need...

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command.html

Communicator

Thanks much, that thread is a good info.

Gleb

0 Karma

SplunkTrust
SplunkTrust

No problem, dont forget to mark the question as answered. Cheers.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!