Using Geo Location Lookup Script

The Geo Location Lookup Script is a lookup script used to provide geolocation information for IP addresses. Looking at the documentation, we see this example:

eventtype=firewall_event | lookup geoip clientip as src_ip 

You can find the documentation for any Splunkbase app by searching for it at https://splunkbase.com, or by clicking on View details on Splunk apps (next to any installed app), clicking on Apps, and viewing the Apps page.

Let's go through the arguments of the lookup command:

  • geoip: This is the name of the lookup provided by Geo Location Lookup Script. You can see the available lookups by going to Settings | Lookups | Lookup definitions.
  • clientip: This is the name of the field in the lookup ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.