GeoIP Databases
How to add GeoIP information to Wireshark
- Download and extract the databases from MaxMind (great name)
- Have to sign up for a free account and GeoLite 2 license
- Navigate to Downloads, and download the ASN, City, and Country databases in GZIP (not the CSV format versions)
- I have them saved/extracted to
C:\Users\user\Documents\Wireshark\MaxMind GeoIP Databases
- I have them saved/extracted to
- You have to extract them not just from the GZ, but also from the TAR
- Activate them in Wireshark
- Edit>Preferences>Name Resolution>MaxMind database directories