Products/Services
product
- Why choose Splunk
- Installation record
- price
- Splunk Enterprise Security
- Splunk Phantom (SOAR)
- Splunk ITSI (Next Generation IT Operations)
- Splunk Observability Cloud
- Splunk UBA
- Macnica CSIRT App Basic
- App for Splunk for Financial Institutions
- Splunk Analytics for Hadoop
- About Apps
- Splunk Edge Hub
- What is Splunk
service
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
Specifications/Technical Information
Specifications/Technical Information
Evaluation machine application/FAQ
Application for evaluation machine
- FAQ
MMDB file update procedure
- release date
- 2018-10-03
- last updated
- 2023-10-02
- version
-
Splunk Enterprise 9.1
- Overview
- The MMDB file (location information) referenced by the iplocation command can be changed.
You can update the MMDB file by changing the limits.conf settings.
- Reference information
-
- MMDB file update procedure
- content
-
When using the iplocation command in Splunk, the MMDB file provided by MaxMind is referenced and the location information is output.
MMDB file update procedure
- Go to $SPLUNK_HOME/etc/system/local on your Splunk server and open limits.conf with a text editor. (If not, create a new limits.conf.)
*The default installation path of $SPLUNK_HOME is as follows.
Linux: /opt/splunk/
Windows: C:\Program Files\splunk- Add the following settings to limits.conf.
==========
[iplocation]
db_path = <更新するMMDBファイルのフルパス>
==========(Example) When updating to "GeoLite2-City.mmdb" located in "$SPLUNK_HOME/etc"
==========
[iplocation]
db_path = $SPLUNK_HOME/etc/GeoLite2-City.mmdb
==========- Please restart the Splunk service.
Supplementary information
If the search head and indexer are separate instances in a distributed environment, update the MMDB files for both the search head and indexer.
that's all
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Weekdays: 9:00-17:00