Security

Monitoring for Emails Sent Externally

ccolbert
Engager

Hello, 

I am looking for assistance developing a Splunk query that will display all users within my organization that have sent 5+ emails to either gmail, yahoo, or hotmail domains within the past hour. 

As an example, if John in Accounting has submitted his resignation and is now performing a data dump by sending small amounts (to evade detection) of data home, I would like to be alerted immediately. 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

See the Splunk Security Essentials app for the "Flight Risk Emailing" use case.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

See the Splunk Security Essentials app for the "Flight Risk Emailing" use case.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...