Splunk Enterprise Security

Identifying events that originate greater than 50 miles from a lon\lat.

bbraun
New Member

Hello,

We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that occur outside a 50 mile radius from each location using their latitude and longitude. The end goal is to set different thresholds for these sites. Id imagine ill need to create a lookup for each locations latitude and longitude for the query to reference.

I'm not exactly sure where to begin and hope you guys can point me in the right direction.

0 Karma

lakshman239
Influencer

Have you looked access anomalies dashboard which is available as part of user activity monitoring? Geographically Improbable Accesses - https://docs.splunk.com/Documentation/ES/5.3.0/User/UserRisk#Access_Anomalies

0 Karma

bbraun
New Member

yea, I figured I could steal logic from the Correlation Search as a plan B. I was hoping someone had already tackled this issue since I dont have a lot of experience building queries.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...