I am fairly new to splunk. I am trying to work out the syntax in order to identify if a staff member has been uploading data to icloud.
I have usernames and IP address.
I can search their username fine, but also cannot confidently aggregate the data shown. I assume an icloud connection might not say "icloud"?
Much appreciated, thank you for your time.
So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
View solution in original post