Splunk Enterprise Security

How to create dashboard that will closely monitor login activity of certain users and the IP address?

AidanMarkSmith
Observer

Hi,

I need some help setting up a dashboard that will allow us to closely monitor login activity of certain users and the IP address' they use to ensure we don't have any exploiters trying to access our systems.

 

Another thing I would like to do, if possible, is to create a dashboard where we can input a username, and then it will show us the login data for that user over a certain period of time.

Regards,

Aidan Smith

Tags (3)
0 Karma

nathanluke86
Communicator

This app does what you need

https://splunkbase.splunk.com/app/4240/

 

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @AidanMarkSmith,

If the instances are on Windows OS, you can try installing and configuring https://splunkbase.splunk.com/app/3177/ add-on in your environment. It is pretty much helpful for auditing purposes. 

A guide on setting this app can be found here - https://splunkbase.splunk.com/app/3177/#/details 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample (anonymised) events that you have ingested into Splunk for this - preferably in a code block </>

0 Karma

AidanMarkSmith
Observer

Hi,

Unfortunately im not sure how to do this as I am still very much new to using Splunk.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...