Alerting

How to create an Alert Connection VPN from foreign source

quangtran
Explorer

how to create an alert detect when there is a VPN connecting from the outside

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What data do you have in your events?

How do you identify if the connection is from "outside"?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @quangtran,

your rerquest is a little vague, could you share more information, some example of your logs and a description of the values to understand sender (src-ip, username, ect...)?

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @quangtran,

if one answer solves your need, please accept one answer for the other people of Community or tell us how we can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors;-)

0 Karma

quangtran
Explorer

sorry, because this warning does not have enough log sources at the moment, i have not continued writing 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @quangtran,

ok, let us know if we can help you more.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma
Get Updates on the Splunk Community!

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...

Splunk Answers Content Calendar, June Edition II

Get ready to dive into Splunk Dashboard panels this week! We'll be tackling common questions around ...

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...