I need a search to add to a dashboard to get my top 5 windows servers with rate of changes to event logs application and system this search would include all events. This would be real time events for past 30 minutes. and if possible i need to get the same search but with top 5 servers with rate of changes with error and warnings only to the application and system event logs. please can someone help as i am new to splunk and need to see if I can get this info.
Start your adventure here and be sure to UpVote
along the way:
https://answers.splunk.com/answers/511894/how-to-use-the-timewrap-command-and-set-an-alert-f.html