For those using Bro with libgeoip for IP location data, such as country of origin, Maxmind has announced that March 2018 will be the last update to the free legacy database:
https://dev.maxmind.com/geoip/geoip2/geolite2/
https://blog.hqcodeshop.fi/archives/387-MaxMind-GeoIP-database-legacy-version-discontinued.html
Some options appear to be:
-
Update Bro to use the new Maxmind library.
-
In the short term, generate legacy databases from the distributed CSVs for the new format from https://dev.maxmind.com/geoip/geoip2/geolite2/ using code like https://github.com/mteodoro/mmutils or https://github.com/dankamongmen/sprezzos-world/blob/master/packaging/geoip/debian/src/geoip-csv-to-dat.cpp (these would need to be modified to create legacy databases from the new format CSVs)…
-
Hope someone does #2 above and provides access to those generated databases.
-
Become a paying customer of Maxmind to continue to access the legacy format databases
-
Switch to another vendor with free IP location data, such as https://lite.ip2location.com/ - requiring a different library to access
-
Do nothing, in which case convergence from reality will gradually emerge.
I would be interested in the group’s thoughts about this.
Jim Mellander, ESNet