Splunk Search

How to identify an 'Upload' in search?

thomashigginson
Path Finder

I'm trying to search for logs relating to an upload of data. For example, a computer uploads a file to dropbox or some external server. What is a keyword used to search and identify that log?

Tags (1)
1 Solution

Ayn
Legend

This depends entirely on what kind of events your logs have related to this and what knowledge objects you have created that can be used for identifying various events. It is not as simple as providing one single keyword. In order for us to be able to give you useful answers, you need to provide much more details on what your logs look like, what different scenarios you're looking at and what tags etc you've built for identifying the events in question.

View solution in original post

Ayn
Legend

This depends entirely on what kind of events your logs have related to this and what knowledge objects you have created that can be used for identifying various events. It is not as simple as providing one single keyword. In order for us to be able to give you useful answers, you need to provide much more details on what your logs look like, what different scenarios you're looking at and what tags etc you've built for identifying the events in question.

Ayn
Legend

No, this would have to be tracked by intermediate devices such as a proxy. If you want to keep better track of a whole chain you would need some kind of DLP tool. Splunk is only as good as the input you feed it, so if you don't have logs providing enough information about that a document was uploaded somewhere, for instance, then Splunk won't be able to magically get that information for you.

thomashigginson
Path Finder

To be more specific, documents(primarily txt documents) uploaded from a computer through the network through the server through the internet to an ip. Is there any Windows event log that signifies data is being copied and uploaded?

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...