Solved: How to display iplocation info for all values in t... - Splunk
https://community.splunk.com/t5/Splunk-Search/How-to-display-iplocation-info-for-all-values-in-the-IP-address/m-p/218732
WEBJun 23, 2016 · Solution. jtacy. Builder. 06-23-2016 04:36 PM. Well, eventstats will let you keep track of how many unique IPs are seen per username so you can sort on that: index=abc username!="xyz" | eventstats dc(src_ip) AS ip_count by username | dedup username,src_ip | table username,src_ip,ip_count | sort -ip_count,-username | iplocation src_ip.
DA: 95 PA: 80 MOZ Rank: 26