Monitoring Splunk

Splunk Cloud Audit Login attempts

broberg
Communicator

In splunk cloud we want to monitor failed login attempts against the Splunk cloud searchhead.
This log is visible under index=_audit but with wrong src IP-address

Audit:[timestamp=09-03-2019 08:02:02.041, user=myuser, action=login attempt, info=failed, src=127.0.0.1][n/a]
Audit:[timestamp=09-03-2019 08:56:42.518, user=myuser, action=login attempt, info=succeeded, src=127.0.0.1][n/a]

However, when doing a REST API Call, i do get the correct Ip-adress (masking it in below example)

Audit:[timestamp=09-03-2019 09:05:52.123, user=myuser, action=login attempt, info=succeeded, src=8.8.8.8][n/a]

Any suggestion, or should i do a request to splunk?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I would submit a Support request.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...