How it works...

Splunk has a built-in external IP address lookup, which is being leveraged in this recipe. Firstly, you specified which dataset field was an IP address. Following this, you configured several Geo IP dataset fields for longitude, latitude, city, region, and country. Behind the scenes, Splunk passes the specified external IP address field into an internal lookup database that returns the values of these additional Geo IP dataset fields.

We chose not to make these required (as is default), because not every event mapped by our Application data model contains an IP address field. As you defined these fields at the root event dataset level in the data model hierarchy, the fields are available to other child datasets in the hierarchy. ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.