Hi everybody,
i need quick help with this:
Please make a corresponding proxy evaluation which servers have accessed which URLs / hosts in the last week.
Thx a lot!!
I'm not a pro. But i think i have everything i need... isn't there a possibility to out in a command and see a list fo servers and urls?
Your data will probably have been ingested into splunk and indexed and categorised into different source types with various fields extracted from the events. These are the basic classes of data you will be dealing with. However, your company may have ingested your data in any number of ways so it is difficult for anyone without that knowledge to tell you what you need to do. Do you know what sources, sourcetypes, indexes, etc. you have in splunk? Do you know which index the data you are interested in has been put in?
We use splunk in our Company. It's connected the to whole infrastructure
Congratulations. So, exactly what data have you put into splunk to allow you to do this evaluation?
What data do you have to make this evaluation from?