As a CISO, you get asked the same question in a dozen different forms, by the board, the executive team, auditors and sometimes regulators: "Are our users secure?" It's a hard one to answer with confidence. Users work from the office, from home and from everywhere in between, on laptops, phones and tablets, as employees, contractors and visitors. The evidence you need sits across network, endpoint and identity tools, each owned by a different team. In this post we show how user activity monitoring with Splunk pulls that evidence into one organisation-wide view, so you can answer with data rather than reassurance.
User activity monitoring is the continuous tracking of how users connect to, authenticate with and behave across an organisation's systems. It covers network access, devices and account activity. It's hard for a CISO because that evidence is spread across separate tools and teams, with no shared timeline and no shared definition of "normal".
You'll probably recognise the symptoms. When the board asks about a headline breach, it takes days to confirm whether you're exposed. Contractors, remote users and unmanaged devices fall into the gaps between tools. And an audit only proves you were compliant on the day, not that you're compliant today.
What you actually need is one continuously updated view of end user risk across the organisation, and one you trust enough to put in front of the board.
Splunk has been part of Cisco since the acquisition in 2024. It sits naturally alongside the Cisco networking, identity and security platforms many Australian enterprises and government agencies already run. The dashboards below were built in Splunk Dashboard Studio using sample data. Each one answers a single question a CISO needs answered.
ASSOCIATED BLOGS:
Every end user security question comes back to three things: who is connecting, what are they connecting with, and what is their account doing once they're in? We've built one dashboard for each.
The panel that matters most at CISO level overlays security incidents on remote-worker volumes over time. It shows whether a rise in incidents tracks a change in how people are working, such as a surge in remote contractor sessions or a new access pattern. That's the kind of insight that shapes where policy and investment go next.
ASSOCIATED BLOGS:
The sample dashboard breaks the fleet into compliant devices, devices running under an exception, and non-compliant devices. It also shows security training completion (people are part of the attack surface too), the split between desktop and mobile, and where each device sits on the map. Select a device type and the whole dashboard filters to match.
Every compliance score opens a drilldown view. That means your team can go from "16% non-compliant" to which devices, which users and what's missing without raising a ticket. Scores can also roll up by business unit, site or region, which is handy when you report risk by division.
Pro-Tip: watch the exceptions as closely as the non-compliant devices. Exceptions granted for a good reason six months ago have a habit of outliving that reason. Give each one an owner and an expiry date, and put both on the dashboard.
ASSOCIATED BLOGS:
An identity monitoring dashboard shows how user accounts are behaving across your Windows and Active Directory (AD) environment. Compromised credentials and privilege misuse remain some of the most common ways attackers get in and move around, so this is where early warning matters most.
The sample dashboard is built entirely from standard Windows security events:
Locked-out accounts (Event ID 4740): often the first visible sign of password spraying.
Privilege escalations (Event ID 4672): special privileges assigned at logon, counted per user. One account sitting far above the rest deserves a question.
Failed vs successful logons (Event IDs 4625 and 4624): trended over time.
Account changes: accounts created, deleted, modified and locked out, each with a sparkline.
Rare AD domains: account domains that seldom appear in the logs, and often a sign of something that doesn't belong.
In the sample data, failed logons outnumber successful ones by about two to one. That doesn't automatically mean an attack. Stale credentials on a phone or a service account can produce exactly the same pattern. But it's exactly the kind of signal a CISO wants surfaced, baselined and explained, not buried in a log file.
ASSOCIATED BLOGS:
Each dashboard is useful on its own. For a CISO, the real value comes when all three sit on the same timeline.
Here's an illustrative example. A contractor account logs in from a location it has never used before. On its own, that could just be travel. The device dashboard shows the laptop has been running under an exception for weeks, with patching overdue. The identity dashboard shows the same account picking up privileges it doesn't normally use.
Three separate teams would each see one odd signal, and probably move on. Correlated in Splunk, it's clearly one incident, and your team can act in minutes rather than finding out days later.
That's where the peace of mind comes from. You'll still get alerts. What changes is that you can see how they connect, and trust that nothing is falling between the cracks.
For Australian organisations, that maps neatly onto the Essential Eight. Patching applications and operating systems, restricting administrative privileges and multi-factor authentication can all be evidenced straight from device and identity data. Critical infrastructure operators under the SOCI (Security of Critical Infrastructure) Act get something just as useful: a risk management program they can demonstrate, not just document.
And for the boardroom itself, an Executive View summarises risk posture in terms directors understand, with the detail one click away if they ask.
ASSOCIATED BLOGS:
A Splunk expert designs the data behind the dashboards: which sources to collect, how to normalise them, and which questions each view answers. The result is reliable insight for the CISO rather than noise or runaway licence costs. The dashboards are what you see. The data design underneath is what makes them trustworthy.
In practice, that starts with bringing in the right sources, such as Windows events, network access control, wireless, VPN, and endpoint and device management, without paying to ingest data nobody uses. Those sources are then mapped to common fields so users, devices and accounts can be correlated. Baselines are set for each user group, site and time of day, so an alert actually means something. From there it's about building views for the people who use them: an executive summary for you and the board, and drilldowns for your analysts and engineers. We've taken the same approach in healthcare, manufacturing and telecommunications.
Here at IPTel, we come at Splunk from the network side. Most of the data behind end user security (wireless, switching, access control and identity) flows through infrastructure we design and support every day. Our Splunk services cover licensing, implementation and ongoing managed services.
ASSOCIATED BLOGS:
User activity monitoring is the continuous tracking of how users connect to, authenticate with and behave across an organisation's systems. It combines network access, device compliance and account activity. That lets security teams spot risky or unusual behaviour early and show evidence that controls are working.
Yes. Splunk ingests network access, device compliance and identity data, then correlates them in dashboards that show end user risk across the whole organisation. That covers employees, contractors and visitors, whether on site or remote.
Start with identity (Windows and AD security events), network access control and VPN, and endpoint or device management. Together, those cover who is connecting, from what, and what their accounts are doing.
A good starting set is 4624 (successful logon), 4625 (failed logon), 4740 (account locked out) and 4672 (special privileges assigned to a new logon). Add account creation, deletion and modification events from there.
Yes. Splunk can evidence several Essential Eight controls, including patching, restricting administrative privileges and multi-factor authentication, by trending device and identity data over time.
Yes. Splunk is part of Cisco and ingests telemetry from Cisco wireless, switching, identity and security platforms, including Cisco XDR. That makes it a natural fit for Cisco-based environments.
Many organisations run Splunk in-house. A Splunk partner helps most with the initial data design and correlation, and with keeping ingestion (and licence cost) under control as the environment grows.
A CISO needs to answer three questions with confidence: who is connecting, from what device, and what is their account doing? User activity monitoring with Splunk brings the answers into one organisation-wide view, with network access, device security and identity dashboards sitting on a single timeline and backed by continuous evidence rather than point-in-time audits. That's what gives you peace of mind, and a clear, defensible answer when the board asks whether your users are secure.
ASSOCIATED BLOGS:
Not sure where to start? Our Splunk Assessment and Security Assessment give your organisation a clear health check on end user, device and identity visibility. If you're looking for a Splunk expert who understands both the data and the network it comes from, get in touch via our contact page or email sales@iptel.com.au.