Audit Logs have visibility into everything that is happening in your Carbon Black Cloud environment. Using Splunk’s built-in iplocation command can further enhance the audit data to quickly identify users who are logging in from unexpected locations.
Required Product: Any
Required Data: Audit Logs (App Input)