Splunk Enterprise Security

How can I filter and track events from users accessing organizations laptop in foreign countries.

sbongomcdonald
New Member

Hello,

I am new to splunk and I need help BIG TIME.

I have been struggling to write a search that can filter events from users accessing organizations laptop in foreign countries (monitoring events of approved travelers to foreign countries with the organizations laptop).

The filtering should display hostnames, webmail connections, and VPN connections.

Additionally, I would want to use a lookup to see prospective travelers so that monitoring can be effecient.

Any suggestion

Thanks in advance

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!