Getting Data In

searching windows event logs for realtime

pboon
New Member

I need a search to add to a dashboard to get my top 5 windows servers with rate of changes to event logs application and system this search would include all events. This would be real time events for past 30 minutes. and if possible i need to get the same search but with top 5 servers with rate of changes with error and warnings only to the application and system event logs. please can someone help as i am new to splunk and need to see if I can get this info.

0 Karma

woodcock
Esteemed Legend

Start your adventure here and be sure to UpVote along the way:
https://answers.splunk.com/answers/511894/how-to-use-the-timewrap-command-and-set-an-alert-f.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...