Deployment Architecture

How can I know if data was stolen(robbed) from servers with searching in logs integrated on splunk?

ibra75
Explorer

hello,
How can I know if data was stolen(robbed) from servers with searching in logs integrated on splunk?
any help is appreciated
thanks.

Labels (1)
Tags (3)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust
Traveling, as oft I'm inclined to do here in the lands of Broadality, I've routinely been the victim, nay, the fool of many a disagreeable happenstance. Recalling, as I will in my hours of twilight, a specific time. Caravanning with mine family, more than a fortnight from home, we happened upon the establishment of one Mr. Ibra. A young old man of about 75, invited us to dine and rest within his Tavern. Suffice it to say, we were much inclined, having been wearied by the road. Upon waking the following morn, we discovered, much to our chagrin, our horses and coach had been stolen(robbed). Slowly our minds recalled the evening prior, and learned of the malice and trickery that was our host. We asked a passer-by, more than one, but not one soul had heard the name Mr. Ibra. He had vanished. In his supposed room lay only a few articles of cloth, and some dust from the beginning of time. But wait! Rejoice! Here lay a rock! A clue! A means to our renewed veneration! "Quick!" we shouted, "follow his trail!", for the rock was an outlier, a piece of the puzzle! We hurdled over logs, and trails, and caches of treasures so rich with nothing on our minds except vengeance. Suddenly, upon the path of our newest enlightenment, we halt, confused. Stretching, there in vast adornment, were the Caves of Splunktonia. Wonderous! Stupendous! ........ Here must our story end. For it is not for me to decide for the reader, nay, the reader must decide upon the path to action. For one soul heads down one cave, the other, another. I shall leave you to your own devices, but know this: Doth ye the knowledge seek?  Therefore then you shall find the meek, but not unto your own, for only with the constant hone, of learned ways of Brothel's stone, the information will appear, and justice will be swift and near. 

MuS
Legend

Awesome, again 🙂

piebob
Splunk Employee
Splunk Employee

you've asked a number of very general questions in this forum, please go through the documentation first, starting with the Search tutorial, here: http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

0 Karma

Peterman
Explorer

@piebob wrote:

you've asked a number of very general questions in this forum, please go through the documentation first, starting with the Search tutorial, here: http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial 


thanks for sharing the search tutorial man i was looking for such thread

0 Karma

piebob
Splunk Employee
Splunk Employee

this question is much too broad. provide context. what data? what logs? what is the situation? do you have Splunk installed?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...