Splunk Enterprise Security

User internal_monitoring Attempt to Login?

morethanyell
Builder

I am investigating on a Geographically Improbable Access notable event. The user internal_monitoring is detected to have successfull logons in 2 different countries. How is this possible? Isn't internal_monitoring a daemon/background process and isn't something that a "human" can use to login?

Please advice. Thanks a lot!

0 Karma

sulakshanaarora
New Member

Hi,

Facing something similar, what was your finding?

0 Karma
Get Updates on the Splunk Community!

App Building 101 - Build Your First App!

WATCH RECORDING NOW   Tech Talk: App Dev Edition Splunk has tons of out-of-the-box functionality, and you’ve ...

Introducing support for Amazon Data Firehose in Splunk Edge Processor

We’re excited to announce a powerful update to Splunk Data Management with added support for Amazon Data ...

The Observability Round-Up: September 2024

What’s up Splunk Community! Welcome to the latest edition of the Observability Round-Up, a monthly series in ...