Splunk Enterprise Security

Splunk Enterprise security

vikram1583
Explorer

in my Splunk ES i want to find below search

  1. Count of New Notables created in last 30 days
  2. Count of Modified Correlation Searches in last 30 days
  3. Time of Notable Closure

Can some one help in sending search please..

Thanks in advance

woodcock
Esteemed Legend

1: Count of New Notables created in last 30 days (run this for Last 30 days on the Timepicker:

`notable` | search eventtype!="notable_suppression*"

2: Count of Modified Correlation Searches in last 30 days. This is NOT a full answer, but a starting place:

index="_audit" AND sourcetype="audittrail" AND savedsearch_name="*"

3: Time of Notable Closure

`notable` | search status_label="closed"
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...