Splunk Search

How can I search for the alerts usecase?

AL3Z
Builder


Hi, Need a search for the below usecase 

Search for alert_type=ufa and alert_name="  suspicious  Downloads"
Please include all  domains present in the domains.csv  from  this search 

We are looking for users that trigger the one above AND this one:

Search for alert_type=ufa and alert_name=" suspicious  uploads"
Please exclude all domains present in the domains.csv  from this search
Thanks...

Thanks...

Labels (4)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @AL3Z,

You didn't provide field names in the events and lookup file. I assume domains.csv is a lookup file in Splunk. Please try below sample; I assumed your event and csv file has a field named "domain"

alert_type=ufa and alert_name="suspicious uploads" NOT [inputlookup domains.csv | fields domain | format]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...