Splunk Enterprise Security

Splunk Enterprise security

vikram1583
Explorer

in my Splunk ES i want to find below search

  1. Count of New Notables created in last 30 days
  2. Count of Modified Correlation Searches in last 30 days
  3. Time of Notable Closure

Can some one help in sending search please..

Thanks in advance

woodcock
Esteemed Legend

1: Count of New Notables created in last 30 days (run this for Last 30 days on the Timepicker:

`notable` | search eventtype!="notable_suppression*"

2: Count of Modified Correlation Searches in last 30 days. This is NOT a full answer, but a starting place:

index="_audit" AND sourcetype="audittrail" AND savedsearch_name="*"

3: Time of Notable Closure

`notable` | search status_label="closed"
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...