All Apps and Add-ons

Translating Business Requirements into Syntax

therevenant
New Member

If you were to query the following:

the total number of quarantined files for a particular End point software

What does that translate to you syntax wise?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's not a business requirement. It's not even a full sentence. Go back and ask the stakeholder to clarify.

---
If this reply helps you, Karma would be appreciated.
0 Karma

therevenant
New Member

I guess at this point, it would be useful in getting your insight.
If you want to understand a new splunk environment, what are things you look for? What searches do you generally perform?

index=* | stats values(index)
sourcetype=* |stats values(sourcetype)

What else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk has an entire document dedicated to understanding a new Splunk environment. See https://docs.splunk.com/Documentation/Splunk/7.2.3/InheritedDeployment/Introduction.

---
If this reply helps you, Karma would be appreciated.
0 Karma

therevenant
New Member

If you wanted to search for quarantined files though, how is that queried through Splunk?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It depends on how information about quarantined files is stored in Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...