Splunk Enterprise Security

Splunk Enterprise security

Explorer

in my Splunk ES i want to find below search

  1. Count of New Notables created in last 30 days
  2. Count of Modified Correlation Searches in last 30 days
  3. Time of Notable Closure

Can some one help in sending search please..

Thanks in advance

Esteemed Legend

1: Count of New Notables created in last 30 days (run this for Last 30 days on the Timepicker:

`notable` | search eventtype!="notable_suppression*"

2: Count of Modified Correlation Searches in last 30 days. This is NOT a full answer, but a starting place:

index="_audit" AND sourcetype="audittrail" AND savedsearch_name="*"

3: Time of Notable Closure

`notable` | search status_label="closed"