Splunk Enterprise Security

How to create dashboard that will closely monitor login activity of certain users and the IP address?

AidanMarkSmith
Observer

Hi,

I need some help setting up a dashboard that will allow us to closely monitor login activity of certain users and the IP address' they use to ensure we don't have any exploiters trying to access our systems.

 

Another thing I would like to do, if possible, is to create a dashboard where we can input a username, and then it will show us the login data for that user over a certain period of time.

Regards,

Aidan Smith

Tags (3)
0 Karma

nathanluke86
Communicator

This app does what you need

https://splunkbase.splunk.com/app/4240/

 

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @AidanMarkSmith,

If the instances are on Windows OS, you can try installing and configuring https://splunkbase.splunk.com/app/3177/ add-on in your environment. It is pretty much helpful for auditing purposes. 

A guide on setting this app can be found here - https://splunkbase.splunk.com/app/3177/#/details 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample (anonymised) events that you have ingested into Splunk for this - preferably in a code block </>

0 Karma

AidanMarkSmith
Observer

Hi,

Unfortunately im not sure how to do this as I am still very much new to using Splunk.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...