Getting Data In

searching windows event logs for realtime

pboon
New Member

I need a search to add to a dashboard to get my top 5 windows servers with rate of changes to event logs application and system this search would include all events. This would be real time events for past 30 minutes. and if possible i need to get the same search but with top 5 servers with rate of changes with error and warnings only to the application and system event logs. please can someone help as i am new to splunk and need to see if I can get this info.

0 Karma

woodcock
Esteemed Legend

Start your adventure here and be sure to UpVote along the way:
https://answers.splunk.com/answers/511894/how-to-use-the-timewrap-command-and-set-an-alert-f.html

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...