How can I create a splunk query that pops an alert when there is a suspicious login simultaneously from two different locations?

New Member

To elaborate,,
I currently have active directory logs on Splunk.
I need to find out the location of login, I have logs coming from all around the world.

Please help

0 Karma


can you post some evnt from the log?

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!