Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to add a clientip field to data sources for the iplocation command?

$
0
0
I have a general question and I am more of a power user than admin level here (but I'm in the process of becoming one). I went to use the `iplocation` command today from a data source (which we do not have - I suppose I need to define those too) but instead data that is simply tossed into indexes. When I examined firewall data, I noticed that there was no field **clientip** and therefore `iplocation` would not work. I know I can tag the **src_ip** field or something of that nature but what if I wanted to normalize this across any data index? Furthermore, if I may make another inquiry - being there are no sourcetypes - just data in indexes, how would one go about defining those from the fields that are extracted? Thank you all!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>