Integrate Splunk® and IPInfo
- Eric Jorgensen
- Aug 5
- 1 min read
In this example we show how simple it is using Dataflect to implement a flexible integration between Splunk and the IPInfo API.
While there is a robust IPInfo App for Splunk maintained by the IPInfo team, this integration using Dataflect provides more flexibility and allows you to more easily future proof against any changes to the API.
In this first example we show how to quickly obtain the following information on an IP address using the dfsearch functionality and reaching out the IPInfo Lite API
as_domain
as_name
asn
continent
content_code
country
country_code

In the below example we show how you can use the dfenrich command to enrich your logs with information returned from the IPInfo Lite API

These examples demonstrate how quickly and easily you can integrate Splunk® and the IPInfo API using Dataflect, but they are only the beginning. There are many other use cases that could be implemented by integrating these two powerful tools.
If you want to see what else is possible, or if you have a specific use case you're trying to implement - reach out to us today at sales@dataflect.com.