Alerting

How to create an Alert Connection VPN from foreign source

quangtran
Explorer

how to create an alert detect when there is a VPN connecting from the outside

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What data do you have in your events?

How do you identify if the connection is from "outside"?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @quangtran,

your rerquest is a little vague, could you share more information, some example of your logs and a description of the values to understand sender (src-ip, username, ect...)?

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @quangtran,

if one answer solves your need, please accept one answer for the other people of Community or tell us how we can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors;-)

0 Karma

quangtran
Explorer

sorry, because this warning does not have enough log sources at the moment, i have not continued writing 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @quangtran,

ok, let us know if we can help you more.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...