Splunk Search

How to identify an 'Upload' in search?

thomashigginson
Path Finder

I'm trying to search for logs relating to an upload of data. For example, a computer uploads a file to dropbox or some external server. What is a keyword used to search and identify that log?

Tags (1)
1 Solution

Ayn
Legend

This depends entirely on what kind of events your logs have related to this and what knowledge objects you have created that can be used for identifying various events. It is not as simple as providing one single keyword. In order for us to be able to give you useful answers, you need to provide much more details on what your logs look like, what different scenarios you're looking at and what tags etc you've built for identifying the events in question.

View solution in original post

Ayn
Legend

This depends entirely on what kind of events your logs have related to this and what knowledge objects you have created that can be used for identifying various events. It is not as simple as providing one single keyword. In order for us to be able to give you useful answers, you need to provide much more details on what your logs look like, what different scenarios you're looking at and what tags etc you've built for identifying the events in question.

Ayn
Legend

No, this would have to be tracked by intermediate devices such as a proxy. If you want to keep better track of a whole chain you would need some kind of DLP tool. Splunk is only as good as the input you feed it, so if you don't have logs providing enough information about that a document was uploaded somewhere, for instance, then Splunk won't be able to magically get that information for you.

thomashigginson
Path Finder

To be more specific, documents(primarily txt documents) uploaded from a computer through the network through the server through the internet to an ip. Is there any Windows event log that signifies data is being copied and uploaded?

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...