Splunk Enterprise Security

How to create dashboard that will closely monitor login activity of certain users and the IP address?

AidanMarkSmith
Observer

Hi,

I need some help setting up a dashboard that will allow us to closely monitor login activity of certain users and the IP address' they use to ensure we don't have any exploiters trying to access our systems.

 

Another thing I would like to do, if possible, is to create a dashboard where we can input a username, and then it will show us the login data for that user over a certain period of time.

Regards,

Aidan Smith

Tags (3)
0 Karma

nathanluke86
Communicator

This app does what you need

https://splunkbase.splunk.com/app/4240/

 

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @AidanMarkSmith,

If the instances are on Windows OS, you can try installing and configuring https://splunkbase.splunk.com/app/3177/ add-on in your environment. It is pretty much helpful for auditing purposes. 

A guide on setting this app can be found here - https://splunkbase.splunk.com/app/3177/#/details 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample (anonymised) events that you have ingested into Splunk for this - preferably in a code block </>

0 Karma

AidanMarkSmith
Observer

Hi,

Unfortunately im not sure how to do this as I am still very much new to using Splunk.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...