Thanks Rich! That answered all my questions, but brought up 2 new questions. We are running SE 9.0.5 so we have the new $SPLUNK_HOME/share/dbip-city-lite.mmdb geo-location DB as you mentioned. Th...
See more...
Thanks Rich! That answered all my questions, but brought up 2 new questions. We are running SE 9.0.5 so we have the new $SPLUNK_HOME/share/dbip-city-lite.mmdb geo-location DB as you mentioned. The reason for this new question is I noticed an IP address yesterday whose City seems to be outdated against the results from iplocation.net. Guessing there is no way to update the new dbip-city-lite.mmdb DB after the initial SE install since Splunk has not divulged the vendor ? Went to the link you provided, and to the 9.0.5 page for iplocation which does state the new vendor's mmdb file name, but the data after that shows how to update MaxMind DB's, GeoLite2-City.mmdb & GeoIP2-City.mmdb , which as you said were replaced in 9.0.0, and are not shipped with version 9.0.5. Is this an oversight in the documentation ? iplocation - Splunk Documentation "Usage The iplocation command is a distributable streaming command. See Command types. The Splunk software ships with a copy of the dbip-city-lite.mmdb IP geolocation database file. This file is located in the $SPLUNK_HOME/share/ directory. Updating the IP geolocation database file Through Splunk Web, you can update the .mmdb file that ships with the Splunk software. The file you update it with can be a copy of one of the following two files. Only those two files are supported. To use these two files, you must have a license for the GeoIP2 City database. File name Description GeoLite2-City.mmdb This is a free IP geolocation database that is updated on its download page on a weekly basis. GeoIP2-City.mmdb This is a paid version of the GeoLite2-City IP geolocation database that is more accurate than the free version. Replacing your mmdb file with one of these two files reintroduces the Timezone field that is absent in the default .mmdb file, but does not reintroduce the MetroCode field. Prerequisites You must have a role with the upload_mmdb_files capability. Steps Go online and find a download page for the binary .tar.gz versions of the GeoLite2-City or the GeoIP2-City database files. Download the binary .tar.gz version of the file (GeoLite2-City or GeoIP2-City) that is most appropriate for your needs. Expand the binary .tar.gz version of the file. The .tar.gz file expands into a folder which contains the GeoLite2-City.mmdb file, or the GeoIP2-City.mmdb file, depending on the download you selected. In Splunk Web, go to Settings > Lookups > GeoIP lookups file. On the GeoIP lookups file page, click Choose file. Select the .mmdb file. Click Save. The page displays a success message when the upload completes."