All Apps and Add-ons

User Login Activity

mikefg
Communicator

With this add-on will I be able to see user login activity with source IP, etc.? I want to be able to monitor when and from where (especially by Country) user accounts are logging in.

Splunk 7.3 Enterprise, on-prem, O365 tenant(s), No Azure AD

0 Karma

mikefg
Communicator

Correction to my post - we do have AzureAD.

The answer is yes, you get ClientIP and can iplocation that value to get Country.

Following the steps was fairly straightforward, but the documentation is a bit behind the current interface meaning the specific steps and screenshots don't always match (Microsoft).

One more catch - the Splunk input setup may not allow you to select the index you want to use, I just edited the inputs.conf file for what I wanted.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...