Splunk Search

How to identify data communications to iCloud - first ever post - new splunk user

Arpanet31
Engager

Hi everyone,

I am fairly new to splunk. I am trying to work out the syntax in order to identify if a staff member has been uploading data to icloud.

I have usernames and IP address.

I can search their username fine, but also cannot confidently aggregate the data shown. I assume an icloud connection might not say "icloud"?

Much appreciated, thank you for your time.

Tags (1)
0 Karma
1 Solution

Arpanet31
Engager

So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
:)

View solution in original post

0 Karma

Arpanet31
Engager

So I have entered username AND icloud and that has given me results. If anyone has a more detailed answer it would be appreciated.
:)

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...