<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simply server activity query in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601967#M11486</link>
    <description>&lt;P&gt;Thank you, that is what I was looking for just to get started.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2022 18:22:39 GMT</pubDate>
    <dc:creator>bbainunc</dc:creator>
    <dc:date>2022-06-15T18:22:39Z</dc:date>
    <item>
      <title>What is a simple server activity query?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601947#M11481</link>
      <description>&lt;P&gt;Looking to brush off the cobwebs of my Splunk use and wanted to find a simple query of server activity/traffic for a server on our domain.&amp;nbsp; If anyone has a basic query they use on a regular basis to see traffic on their servers, I'd appreciate if you could share it, once I get the basic syntax, I can take it from there.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 20:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601947#M11481</guid>
      <dc:creator>bbainunc</dc:creator>
      <dc:date>2022-06-15T20:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Simply server activity query</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601956#M11482</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246912"&gt;@bbainunc&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I hint to follow some training, starting from:&lt;/P&gt;&lt;P&gt;Splunk Search Tutorial&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&lt;/P&gt;&lt;P&gt;getting data in&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Data/Getstartedwithgettingdatain" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in this way you can understand how to take data in Splunk and how to use them.&lt;/P&gt;&lt;P&gt;On the Splunk Channel of YouTube you can also find many useful video that explayin how Splunk works, but anuway starts from the above two points.&lt;/P&gt;&lt;P&gt;About your question is too poor to answer, you should describe:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;which data you are speaking about,&lt;/LI&gt;&lt;LI&gt;if you already have them in Splunk or not.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 17:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601956#M11482</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-15T17:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Simply server activity query</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601964#M11483</link>
      <description>&lt;P&gt;Of course I have reviewed tutorials before posting to this forum, I specifically said server traffic, so that answered the data question.&amp;nbsp; I know this is an easy query, was just looking for a boost to spark my memory Your post was not only unhelpful, but kind of condescending.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:02:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601964#M11483</guid>
      <dc:creator>bbainunc</dc:creator>
      <dc:date>2022-06-15T18:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Simply server activity query</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601965#M11484</link>
      <description>&lt;P&gt;Giuseppe was providing useful information.&amp;nbsp; It is not clear to me what server environment you are using, and if you have tried the use local logs or if you want, in the case of network traffic, to pull in a .pcap file.&amp;nbsp; Also, the answer for server activity changes if you have a linux or a windows server.&amp;nbsp;&amp;nbsp;Giuseppe is pretty good if you can be a bit more specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers and good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:18:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601965#M11484</guid>
      <dc:creator>state_larson_ti</dc:creator>
      <dc:date>2022-06-15T18:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Simply server activity query</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601966#M11485</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246912"&gt;@bbainunc&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Of course I have reviewed tutorials before posting to this forum, I specifically said server traffic, so that answered the data question.&amp;nbsp; I know this is an easy query, was just looking for a boost to spark my memory Your post was not only unhelpful, but kind of condescending.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Security/Use_Cases/Security_Posture/Monitoring_for_network_traffic_volume_outliers/Network_traffic_patterns_between_a_source-destination_pair" target="_blank"&gt;https://lantern.splunk.com/Security/Use_Cases/Security_Posture/Monitoring_for_network_traffic_volume_outliers/Network_traffic_patterns_between_a_source-destination_pair&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This link provides some good examples of looking for network traffic assuming you have a data set ingested.&amp;nbsp; I hope this is helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindest,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;T&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601966#M11485</guid>
      <dc:creator>state_larson_ti</dc:creator>
      <dc:date>2022-06-15T18:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Simply server activity query</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601967#M11486</link>
      <description>&lt;P&gt;Thank you, that is what I was looking for just to get started.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-a-simple-server-activity-query/m-p/601967#M11486</guid>
      <dc:creator>bbainunc</dc:creator>
      <dc:date>2022-06-15T18:22:39Z</dc:date>
    </item>
  </channel>
</rss>

