LoFP LoFP / T1535

T1535

TitleTags
a user with successful authentication events from different ips may also represent the legitimate use of more than one device. filter as needed and/or customize the threshold to fit your environment.
it's possible that a user has unknowingly started an instance in a new region. please verify that this activity is legitimate.
this is a strictly behavioral search, so we define \"false positive\" slightly differently. every time this fires, it will accurately reflect the first occurrence in the time period you're searching over plus what is stored in the cache feature. but while there are really no \\"false positives\\" in a traditional sense, there is definitely lots of noise. this search will fire any time a new country is seen in the **geoip** database for any kind of provisioning activity. if you typically do all provisioning from tools inside of your country, there should be few false positives. if you are located in countries where the free version of **maxmind geoip** that ships by default with splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you.
when a legitimate new user logins for the first time, this activity will be detected. check how old the account is and verify that the user activity is legitimate.