Splunk Enterprise Security

How can I filter and track events from users accessing organizations laptop in foreign countries.

sbongomcdonald
New Member

Hello,

I am new to splunk and I need help BIG TIME.

I have been struggling to write a search that can filter events from users accessing organizations laptop in foreign countries (monitoring events of approved travelers to foreign countries with the organizations laptop).

The filtering should display hostnames, webmail connections, and VPN connections.

Additionally, I would want to use a lookup to see prospective travelers so that monitoring can be effecient.

Any suggestion

Thanks in advance

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...