Splunk Enterprise Security

How can I filter and track events from users accessing organizations laptop in foreign countries.

sbongomcdonald
New Member

Hello,

I am new to splunk and I need help BIG TIME.

I have been struggling to write a search that can filter events from users accessing organizations laptop in foreign countries (monitoring events of approved travelers to foreign countries with the organizations laptop).

The filtering should display hostnames, webmail connections, and VPN connections.

Additionally, I would want to use a lookup to see prospective travelers so that monitoring can be effecient.

Any suggestion

Thanks in advance

0 Karma

Tune In & Win!

Don't miss out on your
chance to take home free
prizes by helping our players
save the Splunk Cloudom!

Dungeons & Data
Monsters: Splunk O11y
Day Editions Games
stream live:
5/4 at 6:30pm PST
5/5 at 7:00pm PST
on