Getting Data In

Monitoring browsing

gruffalo
New Member

I want to create a setup where splunk monitors browsing from Firefox browser on ubuntu machine.
If a user browses a blacklisted website a real time alert is created and admin is notified.

breaking the problem to 2 separate isssue:
1) how do I get splunk to monitor Firefox browser on ubuntu
2) how do I create an alarm that goes to the admin (email, app etc)

Thank you!

0 Karma

inventsekar
SplunkTrust
SplunkTrust

1) how do I get splunk to monitor Firefox browser on ubuntu
a simple browsing log(not sure how to get this).. or, web logs from iis, or firewall logs for your team/group/company would be perfect for this browsing history.


2) how do I create an alarm that goes to the admin (email, app etc)

once you ingested the logs to splunk, then searching and creating alerts(alarm) email notifications is an easy task. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...