[Bro] No future updates to GeoIP legacy databases

Greg Grasmehr greg.grasmehr at caltech.edu
Thu Apr 12 11:43:51 PDT 2018


Hello,

Last I checked (a few years ago) the Maxmind commercial offering was
pretty expensive, so I am interested to find that may no longer be the
case, if you don't mind how much are you paying Isabelle?

We have been using the db-ip API with other processes for quite a while
now as the free Maxmind GeoIP database is often inaccurate.  The db-ip
service is great and the price is super cheap for API use and slightly
more expensive for a DB download which contains necessary data including
LAT and LONG.  Been thinking about incorporating db-ip into Splunk and I
guess now Bro - so this news provides motivation to get that done.

https://db-ip.com

Greg



More information about the Bro mailing list