Getting Data In

searching windows event logs for realtime

pboon
New Member

I need a search to add to a dashboard to get my top 5 windows servers with rate of changes to event logs application and system this search would include all events. This would be real time events for past 30 minutes. and if possible i need to get the same search but with top 5 servers with rate of changes with error and warnings only to the application and system event logs. please can someone help as i am new to splunk and need to see if I can get this info.

0 Karma

woodcock
Esteemed Legend

Start your adventure here and be sure to UpVote along the way:
https://answers.splunk.com/answers/511894/how-to-use-the-timewrap-command-and-set-an-alert-f.html

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...