Alerting

How can I create a splunk query that pops an alert when there is a suspicious login simultaneously from two different locations?

sridhar2901
New Member

To elaborate,,
I currently have active directory logs on Splunk.
I need to find out the location of login, I have logs coming from all around the world.

Please help

0 Karma

felipesewaybric
Contributor

can you post some evnt from the log?

0 Karma