Hello,
I am new to splunk and I need help BIG TIME.
I have been struggling to write a search that can filter events from users accessing organizations laptop in foreign countries (monitoring events of approved travelers to foreign countries with the organizations laptop).
The filtering should display hostnames, webmail connections, and VPN connections.
Additionally, I would want to use a lookup to see prospective travelers so that monitoring can be effecient.
Any suggestion
Thanks in advance
... View more