Splunk® Enterprise

Search Reference

Download manual as PDF

Splunk Enterprise version 5.0 reached its End of Life on December 1, 2017. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

iplocation

Synopsis

Extracts location information from ip addresses.

Syntax

iplocation [maxinputs=<int>]

Optional arguments

maxinputs
Syntax: maxinputs=<int>
Description: Specifies how many of the top results are passed to the script.


Description

Finds IPs in _raw and looks up the IP location using the hostip.info service database. IPs are extracted as ip1,ip2 etc. Cities and countries are likewise extracted. This command requires that the Splunk instance you are running it on have access to the internet.

Examples

Example 1: Add location information (based on IP address).

... | iplocation

Example 2: Search for client errors in Web access events, add the location information, and return a table of the IP address, City and Country for each client error.

404 host="webserver1" | head 20 | iplocation | table clientip, City, Country

Answers

Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the iplocation command.

PREVIOUS
inputlookup
  NEXT
join

This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7, 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters