Files
splunk-security_content/baselines/monitor_successful_backups.yml
2020-04-29 13:01:45 +02:00

19 lines
744 B
YAML

name: Monitor Successful Backups
id: b4d0dfb2-2195-4f6e-93a3-48468ed9734e
version: '1.0'
date: '2017-09-12'
description: This search is intended to give you a feel for how often successful backups
are conducted in your environment. Fluctuations in these numbers will allow you
to determine when you should investigate.
how_to_implement: To successfully implement this search you must be ingesting your
backup logs.
author: David Dorsey, Splunk
search: sourcetype="netbackup_logs" "Disk/Partition backup completed successfully."
| bucket _time span=1d | stats dc(COMPUTERNAME) as count values(COMPUTERNAME) as
dest by _time, MESSAGE
tags:
analytics_story:
- Monitor Backup Solution
detections:
- Unsuccessful Netbackup backups