Splunk Search

How to identify an 'Upload' in search?

thomashigginson
Path Finder

I'm trying to search for logs relating to an upload of data. For example, a computer uploads a file to dropbox or some external server. What is a keyword used to search and identify that log?

Tags (1)
1 Solution

Ayn
Legend

This depends entirely on what kind of events your logs have related to this and what knowledge objects you have created that can be used for identifying various events. It is not as simple as providing one single keyword. In order for us to be able to give you useful answers, you need to provide much more details on what your logs look like, what different scenarios you're looking at and what tags etc you've built for identifying the events in question.

View solution in original post

Ayn
Legend

This depends entirely on what kind of events your logs have related to this and what knowledge objects you have created that can be used for identifying various events. It is not as simple as providing one single keyword. In order for us to be able to give you useful answers, you need to provide much more details on what your logs look like, what different scenarios you're looking at and what tags etc you've built for identifying the events in question.

Ayn
Legend

No, this would have to be tracked by intermediate devices such as a proxy. If you want to keep better track of a whole chain you would need some kind of DLP tool. Splunk is only as good as the input you feed it, so if you don't have logs providing enough information about that a document was uploaded somewhere, for instance, then Splunk won't be able to magically get that information for you.

thomashigginson
Path Finder

To be more specific, documents(primarily txt documents) uploaded from a computer through the network through the server through the internet to an ip. Is there any Windows event log that signifies data is being copied and uploaded?

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...