Splunk Search

iplocation draws blank

gesman
Communicator

This doesn't returns anything:
| stats c | eval ip="107.181.233.178" | iplocation ip allfields=1 | table ip, Country, Region, City
likely due to iplocation's usage of limited geoip DB?

Is there a way (perhaps for an extra fee?) to plug into Splunk more robust and rich IP location and assignment resolution capabilities?

Tags (1)
0 Karma

joshd
Builder

You should reference this already answered question which will be what you need...

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command.html

gesman
Communicator

Thanks much, that thread is a good info.

Gleb

0 Karma

joshd
Builder

No problem, dont forget to mark the question as answered. Cheers.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...