Splunk Search

Search for users logons from different geo locations

ecanmaster
Explorer

I have build a query so far to look at users who log on from 2 different geo locations,
however

index=microsoft  
| iplocation src_ip 
| stats count dc(Country) as "Geo Location" by user 
| search "Geo Location" > 1

However I cant seem to add more info like src dest action etc.
we cant use value's , so that option not available
is there another way to get all the info?
I do realize that I will get more than 1 ip address , but that is the use case

Tags (1)
0 Karma
1 Solution

starcher
Influencer
 base search
| iplocation prefix=srcgeo_ src 
| eventstats dc(srcgeo_Country) as countryCount by user 
| where countryCount>1

View solution in original post

0 Karma

starcher
Influencer
 base search
| iplocation prefix=srcgeo_ src 
| eventstats dc(srcgeo_Country) as countryCount by user 
| where countryCount>1
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...