Splunk Search

How to identify data communications to iCloud - first ever post - new splunk user

Arpanet31
Engager

Hi everyone,

I am fairly new to splunk. I am trying to work out the syntax in order to identify if a staff member has been uploading data to icloud.

I have usernames and IP address.

I can search their username fine, but also cannot confidently aggregate the data shown. I assume an icloud connection might not say "icloud"?

Much appreciated, thank you for your time.

Tags (1)
0 Karma
1 Solution

Arpanet31
Engager

So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
:)

View solution in original post

0 Karma

Arpanet31
Engager

So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
:)

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...