Splunk Search

How to identify data communications to iCloud - first ever post - new splunk user

Arpanet31
Engager

Hi everyone,

I am fairly new to splunk. I am trying to work out the syntax in order to identify if a staff member has been uploading data to icloud.

I have usernames and IP address.

I can search their username fine, but also cannot confidently aggregate the data shown. I assume an icloud connection might not say "icloud"?

Much appreciated, thank you for your time.

Tags (1)
0 Karma
1 Solution

Arpanet31
Engager

So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
:)

View solution in original post

0 Karma

Arpanet31
Engager

So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
:)

0 Karma
Get Updates on the Splunk Community!

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...