Products/Services
product
service
- Simple Security Consulting [Consulting]
- Splunk SOAR Automation Assessment Service [Consulting]
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Splunk Premium Apps construction support service [implementation and construction support]
- Splunk Security Log Analysis Start Package [Original App/Service]
- Splunk × CrowdStrike Falcon Insight, Macnica Original App [Original App/Service]
- Government uniform standard compatible App [Original App/Service]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- SIEM Operation Monitoring Service [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
- Macnica Premium Support for Splunk Skill Up Package
Specifications/Technical Information
Specifications/Technical Information
Evaluation machine application/FAQ
Application for evaluation machine
- FAQ
MMDB file update procedure
- release date
- 2018-10-03
- last updated
- 2023-10-02
- version
- Splunk Enterprise 9.0.1
- Overview
- The MMDB file (location information) referenced by the iplocation command can be changed.
You can update the MMDB file by changing the limits.conf settings.
- Reference information
-
- MMDB file update procedure
- content
-
When using the iplocation command in Splunk, the MMDB file provided by MaxMind is referenced and the location information is output.
MMDB file update procedure
- Go to $SPLUNK_HOME/etc/system/local on your Splunk server and open limits.conf with a text editor. (If not, create a new limits.conf.)
*The default installation path of $SPLUNK_HOME is as follows.
Linux: /opt/splunk/
Windows: C:\Program Files\splunk- Add the following settings to limits.conf.
==========
[iplocation]
db_path = <更新するMMDBファイルのフルパス>
==========(Example) When updating to "GeoLite2-City.mmdb" located in "$SPLUNK_HOME/etc"
==========
[iplocation]
db_path = $SPLUNK_HOME/etc/GeoLite2-City.mmdb
==========- Please restart the Splunk service.
Supplementary information
If the search head and indexer are separate instances in a distributed environment, update the MMDB files for both the search head and indexer.
that's all
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Mon-Fri 8:45-17:30