Hello,
We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that occur outside a 50 mile radius from each location using their latitude and longitude. The end goal is to set different thresholds for these sites. Id imagine ill need to create a lookup for each locations latitude and longitude for the query to reference.
I'm not exactly sure where to begin and hope you guys can point me in the right direction.
couple of accepted answers in this portal that leads to this blog:
http://www.sedward5.com/detecting-credential-theft-using-splunk-geographic-information/
here are the answers:
https://answers.splunk.com/answers/219607/how-to-search-concurrent-logins-from-geographicall.html
https://answers.splunk.com/answers/169873/how-to-set-up-an-alert-to-detect-login-abuse-and-c.html
hope it helps
Have you looked access anomalies dashboard which is available as part of user activity monitoring? Geographically Improbable Accesses - https://docs.splunk.com/Documentation/ES/5.3.0/User/UserRisk#Access_Anomalies
yea, I figured I could steal logic from the Correlation Search as a plan B. I was hoping someone had already tackled this issue since I dont have a lot of experience building queries.