Splunk Enterprise Security

Splunk Enterprise security

vikram1583
Explorer

in my Splunk ES i want to find below search

  1. Count of New Notables created in last 30 days
  2. Count of Modified Correlation Searches in last 30 days
  3. Time of Notable Closure

Can some one help in sending search please..

Thanks in advance

woodcock
Esteemed Legend

1: Count of New Notables created in last 30 days (run this for Last 30 days on the Timepicker:

`notable` | search eventtype!="notable_suppression*"

2: Count of Modified Correlation Searches in last 30 days. This is NOT a full answer, but a starting place:

index="_audit" AND sourcetype="audittrail" AND savedsearch_name="*"

3: Time of Notable Closure

`notable` | search status_label="closed"
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...