Splunk Enterprise Security

How to create dashboard that will closely monitor login activity of certain users and the IP address?

AidanMarkSmith
Observer

Hi,

I need some help setting up a dashboard that will allow us to closely monitor login activity of certain users and the IP address' they use to ensure we don't have any exploiters trying to access our systems.

 

Another thing I would like to do, if possible, is to create a dashboard where we can input a username, and then it will show us the login data for that user over a certain period of time.

Regards,

Aidan Smith

Tags (3)
0 Karma

nathanluke86
Communicator

This app does what you need

https://splunkbase.splunk.com/app/4240/

 

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @AidanMarkSmith,

If the instances are on Windows OS, you can try installing and configuring https://splunkbase.splunk.com/app/3177/ add-on in your environment. It is pretty much helpful for auditing purposes. 

A guide on setting this app can be found here - https://splunkbase.splunk.com/app/3177/#/details 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample (anonymised) events that you have ingested into Splunk for this - preferably in a code block </>

0 Karma

AidanMarkSmith
Observer

Hi,

Unfortunately im not sure how to do this as I am still very much new to using Splunk.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...