Splunk Enterprise Security

How to create dashboard that will closely monitor login activity of certain users and the IP address?

AidanMarkSmith
Observer

Hi,

I need some help setting up a dashboard that will allow us to closely monitor login activity of certain users and the IP address' they use to ensure we don't have any exploiters trying to access our systems.

 

Another thing I would like to do, if possible, is to create a dashboard where we can input a username, and then it will show us the login data for that user over a certain period of time.

Regards,

Aidan Smith

Tags (3)
0 Karma

nathanluke86
Communicator

This app does what you need

https://splunkbase.splunk.com/app/4240/

 

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @AidanMarkSmith,

If the instances are on Windows OS, you can try installing and configuring https://splunkbase.splunk.com/app/3177/ add-on in your environment. It is pretty much helpful for auditing purposes. 

A guide on setting this app can be found here - https://splunkbase.splunk.com/app/3177/#/details 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample (anonymised) events that you have ingested into Splunk for this - preferably in a code block </>

0 Karma

AidanMarkSmith
Observer

Hi,

Unfortunately im not sure how to do this as I am still very much new to using Splunk.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...