Hello there,
In Cloud Splunk is there a way however an alert could be created for example: attacker logs in from London and the user is based in London, how do we identify them?
As i know we can do this via Country level based on Geo Tagging of IPs but can we configure this to drill down at location level ? if so how?
Many Thanks,
Mozza