Hello,
We analise syslog msg from dhcpd daemon.
And want use GeoIP, but we use internal ip addresses.
How match internal ip or host name to City.
For example,
@timestamp August 29th 2017, 12:39:10.754
host 172.xx.xx.x
host_name krg2-fw
message <190> 2017 Aug 29 11:37:59 krg2-fw local7.info dhcpd: [Local Network: DHCP] DHCPACK on 10.x.x.x to 68:f7:xx:xx (xxx) via LAN1
srcip 10.x.x.x
172.xx.xx.x = krg2-fw = >Krasnodar
How match interlan IP or hostname with City?
The city name over 150.
We have two way.
- Edit geoip DB manual
- use external csv (txt etc) file, where match hostname or ip with City
How can do this ?