Splunk Enterprise Security

How can I filter and track events from users accessing organizations laptop in foreign countries.

sbongomcdonald
New Member

Hello,

I am new to splunk and I need help BIG TIME.

I have been struggling to write a search that can filter events from users accessing organizations laptop in foreign countries (monitoring events of approved travelers to foreign countries with the organizations laptop).

The filtering should display hostnames, webmail connections, and VPN connections.

Additionally, I would want to use a lookup to see prospective travelers so that monitoring can be effecient.

Any suggestion

Thanks in advance

0 Karma
Get Updates on the Splunk Community!

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...