Splunk Search
Highlighted

iplocation draws blank

Communicator

This doesn't returns anything:
| stats c | eval ip="107.181.233.178" | iplocation ip allfields=1 | table ip, Country, Region, City
likely due to iplocation's usage of limited geoip DB?

Is there a way (perhaps for an extra fee?) to plug into Splunk more robust and rich IP location and assignment resolution capabilities?

Tags (1)
0 Karma
Highlighted

Re: iplocation draws blank

SplunkTrust
SplunkTrust

You should reference this already answered question which will be what you need...

http://answers.splunk.com/answers/123430/how-to-update-geoip-database-for-iplocation-command.html

Highlighted

Re: iplocation draws blank

Communicator

Thanks much, that thread is a good info.

Gleb

0 Karma
Highlighted

Re: iplocation draws blank

SplunkTrust
SplunkTrust

No problem, dont forget to mark the question as answered. Cheers.

0 Karma