All Apps and Add-ons

Translating Business Requirements into Syntax

therevenant
New Member

If you were to query the following:

the total number of quarantined files for a particular End point software

What does that translate to you syntax wise?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's not a business requirement. It's not even a full sentence. Go back and ask the stakeholder to clarify.

---
If this reply helps you, Karma would be appreciated.
0 Karma

therevenant
New Member

I guess at this point, it would be useful in getting your insight.
If you want to understand a new splunk environment, what are things you look for? What searches do you generally perform?

index=* | stats values(index)
sourcetype=* |stats values(sourcetype)

What else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk has an entire document dedicated to understanding a new Splunk environment. See https://docs.splunk.com/Documentation/Splunk/7.2.3/InheritedDeployment/Introduction.

---
If this reply helps you, Karma would be appreciated.
0 Karma

therevenant
New Member

If you wanted to search for quarantined files though, how is that queried through Splunk?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It depends on how information about quarantined files is stored in Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...