All Apps and Add-ons

Help creating two CWS searches

dzejsonborn
New Member

Hi, I am quite new with SPL searches and I need to urgently create the below searches, anyone can help?

- executable files download (.exe should be excluded due to the amount)

- big uploads made by users to external hosts

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Assuming you have data available about the uploads and download made by users, both searches are possible. See the Splunk Security Essentials app (https://splunkbase.splunk.com/app/3435/) for examples.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming you have data available about the uploads and download made by users, both searches are possible. See the Splunk Security Essentials app (https://splunkbase.splunk.com/app/3435/) for examples.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...