Splunk Search

how we can identify peoples region in Splunk ?

nikhilagrawal
Path Finder

Hello Team,

We have use case where we need to map/identify people's region in Splunk and create dashboard. Can we do something in Splunk?
we want to be able to write some performance dashboards and categorise people as internal/external and what region (UK/US/APAC/Other)

thanks
Nik

Tags (1)
0 Karma

nikhilagrawal
Path Finder

Its mainly application logs indexed to Splunk and we are trying to create performance dashboard categorise people as internal/external and region (UK/US/APAC/Other).

0 Karma

PPape
Contributor

Can you give some more information?
What Datasources do you have?

It is possible to make performance dashboards and filter to regions.

I did something like this. A Worldmap where the locations with a bad latency get marked.

0 Karma

nikhilagrawal
Path Finder

Its mainly application logs indexed to Splunk and we are trying to create performance dashboard categorise people as internal/external and region (UK/US/APAC/Other).

0 Karma

PPape
Contributor

Ok, how can you seperate them? Are they all in an Active Directory?
Do they use diffrent subnets?

0 Karma

nikhilagrawal
Path Finder

all users are in Active directory

0 Karma

PPape
Contributor

ok then you can use this data. Why don't you use the "c" attribute of the user? normally there should the country of the user be. and you could use the department attribute for the external users.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...