Security

[Security] Monitor Bulk Queries / Downloads from DB and File Servers

ryantwx33
New Member

Hi Splunkers,

Is there a good way to detect bulk queries conducted in the database, or bulk download of data in database and file servers? If there is, what are the relevant logs/sourcetypes that I should pull from the DB/file servers?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...