Getting Data In

Splunk Dashboard Query to List when CD Drive is access and Written to

Rosie2287
Explorer

Is there a Splunk query I can use to list when CD drive is access and written to and the users associated with those actions made

Labels (3)
0 Karma

Rosie2287
Explorer

New splunk user here - 

No, I was looking for a query I could add to my dashboard that would look in system logs that would check for when the CD drive is accessed or burned to.  

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If the system logs have been ingested into Splunk, you need to identify which events in those logs include the information you are looking for. You can then tell Splunk how to pull out those events so you can report on them in your dashboard. We do not have access to your data, it is only something that you can determine

0 Karma

Rosie2287
Explorer

Ok thank you.  I am not sure about which events report CD Drive actions.  I was just wondering if there was a general dashboard query that could be used to identify cd drive usage.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Probably not - Splunk is a generalised tool for analysing logs not a windows-specific tool

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Is this information in a log somewhere that you have ingested into Splunk?

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...