Title of the alert: “Overseas Successful Login”
Description: Alerts if a successful login is made from a suspected overseas IP address.
Options:
- It is possible to ignore specific IP addresses
- It is possible to ignore specifics users
The problem: This alert is triggered when a login is detected from a suspected overseas location.
Impact: If it is from overseas, and you do not have any staff members overseas, then it may be an indication of an account breach (intrusion).
Suggested steps: Engage a technician to confirm that the alert is accurate, and if so then the technician should suggest and undertake suitable mitigation steps to remedy the situation.