Hi, i have field IP ADDRESS when user login, so i want to alert email when to have a new ip address.
Can you help me
Hi
Here is an old answer for this case https://community.splunk.com/t5/Security/How-can-I-detect-when-a-new-IP-is-used-by-a-user/td-p/21107...
r. Ismo
I read the post but i don't understand. I have to run command in image in search splunk ???? OR how can i configure in edit alert ???
A previous post show to you how you can find a new IPs for user. Then you just create an alert (Save As -> Alert) which send that result to you or where ever you want to send it.
https://docs.splunk.com/Documentation/Splunk/latest/Alert/Definescheduledalerts