I could solve the problem - it works now! The problem was the missing GeoLite mmdb in the data folder of the app. It seems to be that some information (e.g. city, country etc.) comes from this database and I only had the GeoIP mmdb for getting further details (e.g. ISP etc.).
... View more
Much appreciate the reply. The reason I didn't go this route is that I don't have access to Splunk to be able to diddle the transform.conf file, I only have access to the gui. Looks like I'll have to work with the Splunk Admins to work this out.
... View more