Splunk Search

overridding incorrect MAXMIND data

ehoward
Path Finder

Will, the MAXMIND app is incorrectly identifying an IP address in Centreville, Va as being in Miami, Fl. What is the best way to correct this error? Do you recommend editing geoip.py or is there someway to edit GeoLiteCity.dat to correct the bad data?

Tags (2)
0 Karma

mw
Splunk Employee
Splunk Employee

GeoLiteCity.dat is a binary file. You could read through MAXMIND/bin/init.py and figure out how to write it out, change it, and then write it back. But, depending on what you're doing, you may also be able to override the results from it with another lookup command as well that references your own csv file with the relevant data.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...