Splunk Search

How can we search for the Notable Alerts that Does NOT contains any of the contributing events?

Sara01
Observer

IF any one can provide for me meaningful Query - So, I can search for any alerts in our Splunk that does not contains any result for contributing events ,, 

 

Thanks Alot. 

 

 

 

Labels (3)
0 Karma

manjunathmeti
Champion

Provide some sample data and contributing events.

0 Karma

Sara01
Observer

Yes Dear manjunathmeti, 

No I want for any alerts in our environment that when we click on the ContrubutingEvents  within of the incident review --> We can not see anything (anyData) on them ...

How can we search for that .. is there any recommended query? 

 

Thanks. 

0 Karma

Sara01
Observer

Any Answer please .. Help me on that regards. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...