<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bulk System Deletion Creating a Unified Search Query. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652931#M225630</link>
    <description>&lt;LI-CODE lang="markup"&gt;| bin _time span=1m
| stats count by _time eventID&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 02 Aug 2023 17:49:24 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-08-02T17:49:24Z</dc:date>
    <item>
      <title>How to create Bulk System Deletion Creating a Unified Search Query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652903#M225616</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I'm trying to create a&amp;nbsp; search to identify instances of bulk system deletions that took place within a one-minute time frame, and describe a method to consolidate all these results into a single search query.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 07:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652903#M225616</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-23T07:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652905#M225618</link>
      <description>&lt;P&gt;Are you just looking for certain events in your logs with various criteria?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so, perhaps you could share some anonymised events that you are dealing with?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 14:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652905#M225618</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-02T14:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Bulk System Deletion Creating a Unified Search Query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652912#M225621</link>
      <description>&lt;P&gt;..&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 07:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652912#M225621</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-23T07:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652914#M225623</link>
      <description>&lt;P&gt;Not sure what you have posted here - is your event from &amp;lt;event&amp;gt; to &amp;lt;/event&amp;gt; and the rest trying to show what fields you have already extracted (complete with field values running into the next field name)?&lt;/P&gt;&lt;P&gt;Please repost in a codeblock (using the &amp;lt;/&amp;gt; button to create a block to paste the event into).&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 15:01:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652914#M225623</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-02T15:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652920#M225626</link>
      <description>&lt;DIV&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Yeah, These are all the events respective to there event codes.&lt;BR /&gt;Do we need to have the all the event codes in the single event ?&amp;nbsp;&lt;BR /&gt;OR its fine to have the all in the individual events ?&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Aug 2023 16:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652920#M225626</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-02T16:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652925#M225627</link>
      <description>&lt;P&gt;Single events are fine - I assume _time has already been set to the event creation time or whatever you need it to be? Or do you need help extracting the event id and time?&lt;/P&gt;&lt;P&gt;Assuming you have the values already extracted, are you just looking for a way to determine if 100 (or more) events (of a particular type) have occurred in the same minute, or somehow determine, for each event, whether 99 of the same event type have occurred in the previous 60 seconds?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 16:57:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652925#M225627</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-02T16:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652928#M225629</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;I have just posted a single event from each of the specific eventcode events.&lt;BR /&gt;I&amp;nbsp;&lt;SPAN&gt;need help in creating a correlation search for above scenario like when ever any&amp;nbsp;Ad machines deleted from the AD environment&amp;nbsp; for 100 events in a minute the alert should triggered like wise&amp;nbsp;user account deletion&amp;nbsp; and ad machine disabled for 100 events in a minute, and when&amp;nbsp;user added to group it should trigger an alert.&lt;BR /&gt;I&lt;/SPAN&gt;&amp;nbsp;am looking for a way to determine if 100 (or more) events (of a particular type) have occurred in the same minute.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 17:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652928#M225629</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-02T17:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652931#M225630</link>
      <description>&lt;LI-CODE lang="markup"&gt;| bin _time span=1m
| stats count by _time eventID&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 02 Aug 2023 17:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652931#M225630</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-02T17:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652932#M225631</link>
      <description>&lt;P&gt;Can we make a single search using all these Eventcodes ?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 17:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652932#M225631</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-02T17:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652933#M225632</link>
      <description>&lt;P&gt;Yes, because the stats is by time and eventId you will get a line for each event type for each minute some events occurred in - you just have to filter by event type and relevant count&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where (eventID="4743" AND count &amp;gt;= 100) OR (eventID= ...) etc.&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 02 Aug 2023 18:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/652933#M225632</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-02T18:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653053#M225657</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| bin _time span=1m
| stats count by _time eventID&lt;/PRE&gt;&lt;P&gt;is not working as expected if I go with the last 30 days it is showing results why so ?&lt;BR /&gt;then what is the use of bin _time span=1m.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 12:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653053#M225657</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-03T12:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653055#M225658</link>
      <description>&lt;P&gt;I am not sure I understand the question - your requirement was for counts in the last minute, why are you now talking about 30 days? Are you running the search over the last 30 days? That is an awful lot of minutes!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 13:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653055#M225658</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-03T13:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653058#M225661</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I opted for a 30-day trial to see if there were any noticeable outcomes. As I dnt see any alerts for the last 30 days!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 13:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653058#M225661</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-03T13:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653064#M225664</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;How do we enhance this search&amp;nbsp; as per the use case ..&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz sourcetype=X
((EventCode=4743 AND NOT TargetUserName="Win")
OR (EventCode=4726 AND NOT TargetUserName="EC")
OR (EventCode=4725 AND (NOT TargetUserName="WinDi" OR TargetUserName="EC_GMS"))
OR (EventCode=4728 AND NOT TargetUserName="None")
)
| stats count, values(signature) as event_detail, values(TargetUserName) as target_name by Computer, EventCode
| where count &amp;gt; 1 AND EventCode=4728
| bin _time span=1m
| where count &amp;gt;= 100&lt;/LI-CODE&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 09:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653064#M225664</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-07T09:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653067#M225665</link>
      <description>&lt;P&gt;Are you sure there should have been any? How about if you reduced it to 10 in a minute?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 13:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653067#M225665</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-03T13:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653069#M225666</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=xyz sourcetype=X
((EventCode=4743 AND NOT TargetUserName="Win")
OR (EventCode=4726 AND NOT TargetUserName="EC")
OR (EventCode=4725 AND (NOT TargetUserName="WinDi" OR TargetUserName="EC_GMS"))
OR (EventCode=4728 AND NOT TargetUserName="None")
)
| bin _time span=1m
| stats count, values(signature) as event_detail, values(TargetUserName) as target_name by _time, Computer, EventCode
| where (count &amp;gt; 1 AND EventCode=4728) OR count &amp;gt;= 100&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 03 Aug 2023 13:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653069#M225666</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-03T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653072#M225668</link>
      <description>&lt;P&gt;Yes there should be!&lt;/P&gt;&lt;P&gt;I have made a changes to search now I can see the alerts&lt;BR /&gt;thanks....&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 14:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653072#M225668</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-03T14:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653377#M225797</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In order to find out if and when a member was added to a security group,I have done a search for EventCode=4728. The search returned the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;08/02/2023 01:10:24 PM

LogName=Security

SourceName=Microsoft Windows security auditing.

EventCode=4728

EventType=0

Type=Information

ComputerName=server1.domainname.com

TaskCategory=Security Group Management

OpCode=Info

RecordNumber=5551234

Keywords=Audit Success

Message=A member was added to a security-enabled global group.

Subject:

Security ID: domainname\jdoe
Account Name: jdoe
Account Domain: domainname
Logon ID: 0x1e3ef1d1
Member:

Security ID: domainname\jdoe
Account Name: CN=John Doe,OU=My Users OU,DC=domainname,DC=com
Group:

Security ID: domainname\Test Users
Group Name: Test Users
Group Domain: domainname
Additional Information:
Privileges: -&lt;/LI-CODE&gt;&lt;P&gt;Once I viewed this information I changed my search to look like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EventCode=4727 |rename Account_Name as Modifier | rename Group_Name as "Modified Group" |table _time, Host, Modifier, "Modified Group", user&lt;/LI-CODE&gt;&lt;P&gt;My problem is that I don't know how to deal with the two account names when I display the information in a table. The Modifier displays the right information which is the first account name. I would like user to display the information from "Account Name: CN=John Doe,OU=My Users OU,DC=domainname,DC=com" and label it as "Member Added" as that is the member that was added to the Test Users group name.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 09:10:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653377#M225797</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-07T09:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk System Deletion Creating a Unified Search Query.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653385#M225798</link>
      <description>&lt;P&gt;One way to do this (assuming your raw events are the XML event you showed earlier) is to create the appropriate eval commands and execute them with map - it should be noted that map has a limit to the number of searches to prevent excessive resource usage.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath Event.EventData.Data output=EventData
| spath Event.EventData.Data{@Name} output=EventDataName
| eval name_value=mvzip(EventDataName,EventData,"=\"")
| eval name_value=mvmap(name_value,"| eval ".name_value."\"")
| eval name_value=mvjoin(mvappend("| makeresults | eval _raw=\""._raw."\"",name_value),"
")
| map maxsearches=100  search="| makeresults | map search="$name_value$&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 07 Aug 2023 09:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/653385#M225798</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-07T09:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to create Bulk System Deletion Creating a Unified Search Query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/654966#M226252</link>
      <description>&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 07:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-Bulk-System-Deletion-Creating-a-Unified-Search/m-p/654966#M226252</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-08-23T07:12:23Z</dc:date>
    </item>
  </channel>
</rss>

