Splunk Search

map generated ip (fake ip) to longtitude and latitude to use geoip,geostats, iplocation etc

weicheng98
Path Finder

Hi,

I would like to know is it possible to map the longtitude and latitude to a generated ip so that I can visualise it on a world map ?

If it is possible, can you give me an example on how to do so.

0 Karma
1 Solution

niketn
Legend

@weicheng98, you should use stats command to plot statistics by IPs and then use iplocation command to get the latitude and longitude for known ip addresses then use geostats command for stats based on IPs on map. You can also get the Splunk Dashboard Examples App to see the examples for plotting data on map.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

@weicheng98, you should use stats command to plot statistics by IPs and then use iplocation command to get the latitude and longitude for known ip addresses then use geostats command for stats based on IPs on map. You can also get the Splunk Dashboard Examples App to see the examples for plotting data on map.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

weicheng98
Path Finder

Hi @niketnilay, thanks for your answer. But my IPs are not real IPs (i.e. generated) because it is generated by a traffic generator. So when I use the iplocation command, it is not able to retrieve the latitude and longitude or even the country of where the ip originated from.

In the iplocation documentation, may I ask why is the example answer tutorial data able to retrieve details of the IPs e.g. country,city using iplocation ?

0 Karma

xpac
SplunkTrust
SplunkTrust

The IPs used in the example are "real" IPs, meaning they are valid public IPv4 adresses. If you choose the right addresses for your example data, you can map them to a location - it just depends on the IPs you use and if they're available in the Geo IP database.

0 Karma

weicheng98
Path Finder

Hi @xpac, thanks for your answer. Then if that's the case, is it possible to update the Geo IP database manually by myself if the ip I have is not found in the database ?

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...