I am fairly new to splunk. I am trying to work out the syntax in order to identify if a staff member has been uploading data to icloud.
I have usernames and IP address.
I can search their username fine, but also cannot confidently aggregate the data shown. I assume an icloud connection might not say "icloud"?
Much appreciated, thank you for your time.