Splunk Search

How to generate a search to see which users have signed in from a different country other than the U.S. in the last 24 hours?

rodiers01
New Member

Good afternoon all

I'm just looking for a search that will search for anyone that has logged in to a web site, from a different Country (other than the U.S.), in the last 24 hours. Thank you.

0 Karma
1 Solution

rjthibod
Champion

Does this give you results?

index="iis_log" cs_username !=OTHER | dedup c_ip | iplocation prefix=cip_ c_ip

If so, try this

index="iis_log" cs_username !=OTHER | dedup c_ip | iplocation prefix=cip_ c_ip | search cip_Country !="United States"

View solution in original post

0 Karma

rjthibod
Champion

Does this give you results?

index="iis_log" cs_username !=OTHER | dedup c_ip | iplocation prefix=cip_ c_ip

If so, try this

index="iis_log" cs_username !=OTHER | dedup c_ip | iplocation prefix=cip_ c_ip | search cip_Country !="United States"

0 Karma

DalJeanis
Legend

Please promote your comment to an answer, so the poster can accept it.

0 Karma

rodiers01
New Member

BINGO! Good call with that last query. That's exactly what I needed!

The help is top notch over here.

0 Karma

rodiers01
New Member

Cisco Security Suite, IIS Logging, Splunk App for Web Analytics, MS Windows AD Objects, Splunk App for Windows Infrastructure, Splunk Supporting Add-on for AD.

0 Karma

rjthibod
Champion

The community cannot efficiently help you unless you share information about the log / data sources you have available to you. Please share more information about the sourcetypes, log types. add-ons, etc. that are applicable to you.

rodiers01
New Member

The query below that I'm trying isn't giving me any results either when I know It should be....

index="iis_log" cs_username !=OTHER | dedup c_ip | iplocation prefix=cip_ c_ip | search cip_Country !=United States

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...