Splunk Enterprise Security

Geographically Improbable Access Detected ES tuned

Splunk_rocks
Path Finder

Hello,

following ES CS was triggering lot of notable events "Geographically Improbable Access Detected " did any one had luck to tune this and whit listed unwanted stuff. Please share your experience to fix this one.
any alternative search we can use ? let me know your thoughts .
TIA

0 Karma

jbillings
Path Finder

Not sure if this is what you mean by tuning, but here it goes.

Access - Geographically Improbable Access Detected - Rule uses the index=gia_summary, which is populated by the Access - Geographically Improbable Access - Summary Gen. You can add a |search to the end of the original search, and add your exclusions there.  Such as | search src!=8.8.8.8  Depends on how wide of an exclusion you need, you may be better off using a lookup table to add exclusions.

Hope this helps.

0 Karma

jawaharas
Motivator

The Correlation search 'Access - Geographically Improbable Access - Summary Gen' is the one which is actually generated events into 'gia_summary' index.

If you have to whitelist users, ip addresses, locations etc., you can append on this search.

Logic behind this query can be referred here - https://answers.splunk.com/answers/560188/logic-behind-geographically-improbable-access-dete.html

0 Karma

Splunk_rocks
Path Finder

Hey I was aware of that answers earlier please dont post again any splunk question here - This is not the answer im expecting.

0 Karma

jawaharas
Motivator

@Splunk_rocks
Kindly accept the answer it it helped you, so others can refer it.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...