The Geo Location Lookup Script is a lookup script used to provide geolocation information for IP addresses. Looking at the documentation, we see this example:
eventtype=firewall_event | lookup geoip clientip as src_ip
You can find the documentation for any Splunkbase app by searching for it at https://splunkbase.com, or by clicking on View details on Splunk apps (next to any installed app), clicking on Apps, and viewing the Apps page.
Let's go through the arguments of the lookup command:
- geoip: This is the name of the lookup provided by Geo Location Lookup Script. You can see the available lookups by going to Settings | Lookups | Lookup definitions.
- clientip: This is the name of the field in the lookup ...