Splunk® Enterprise

Knowledge Manager Manual

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
Acrobat logo Download topic as PDF

Add a Geo IP field

You can add a Geo IP field to any dataset in your data model that already has a field with a Type of ipv4 in its field list. The ipv4 field must appear above the location for the Geo IP field, and it cannot already be in use for a different Geo IP field calculation.

The Geo IP field is a type of lookup. It reads the IP address values in your dataset's events and can add the related longitude, latitude, city, region, and country values to those events.

  1. In the Data Model Editor, open the dataset you'd like to add a field to.
  2. Click Add Field and select Geo IP to define a Geo IP field.
    The "Add Geo Fields with an IP Lookup" page opens.
  3. Choose the IP field that you want to match, if more than one exists for the selected dataset.
  4. Select the fields that you want to add to your dataset.
  5. (Optional) Rename selected fields by changing their Display Name.
    Display names cannot include asterisk characters.
  6. (Optional) Click Preview to verify that the Geo IP field is correctly updating your events with the Geo IP fields that you have selected.
    You should see events in table format with the new Geo IP field(s) included as columns. For example, if you're working with an event-based dataset and you've selected the City, Region, and Country Geo IP fields, the preview event table should display City, Region, and Country columns to the right of the first column (_time).
    The preview pane has two tabs. Events is the default tab. It presents the events in table format. Select the Values tab to review the distribution of Geo IP field values among your events.
    If you're not seeing the range of values you're expecting, try increasing the preview event sample. By default this sample is set to the first thousand events. You might increase it by setting the Sample value to First 10,000 events or Last 7 days.
    6.1 dm add geoip att prev.png
  7. Click Save to save your changes.
    You will be returned to the Data Model Editor. The Geo IP fields that you have defined will be added to the dataset's set of Calculated fields.
    Note: Geo IP fields are added to your dataset as required fields, and their Type values are predetermined. You cannot change these values.
Last modified on 20 June, 2019
PREVIOUS
Add a regular expression field
  NEXT
Overview of summary-based search acceleration

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.5, 8.0.10, 7.2.1, 7.0.1, 8.0.4, 8.0.9, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.2.0, 8.0.6, 8.0.7, 8.0.8


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters