<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I audit changes made to Splunk Role Index access? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290339#M7757</link>
    <description>&lt;P&gt;Can someone point me in the right direction to find info concerning  auditing Splunk Cloud role changes?  Specifically, I need to find out who/when an index access change occurred for a role in our Splunk Cloud deployment.  I have tried searching the &lt;EM&gt;audit index, yet I don't get any info that says: `this user account&lt;/EM&gt;________ on this date__________ modified the index access list for this role________`?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 21:07:57 GMT</pubDate>
    <dc:creator>nthornbury</dc:creator>
    <dc:date>2017-07-05T21:07:57Z</dc:date>
    <item>
      <title>How can I audit changes made to Splunk Role Index access?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290339#M7757</link>
      <description>&lt;P&gt;Can someone point me in the right direction to find info concerning  auditing Splunk Cloud role changes?  Specifically, I need to find out who/when an index access change occurred for a role in our Splunk Cloud deployment.  I have tried searching the &lt;EM&gt;audit index, yet I don't get any info that says: `this user account&lt;/EM&gt;________ on this date__________ modified the index access list for this role________`?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290339#M7757</guid>
      <dc:creator>nthornbury</dc:creator>
      <dc:date>2017-07-05T21:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I audit changes made to Splunk Role Index access?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290340#M7758</link>
      <description>&lt;P&gt;@nthornbury - Were you ever able to get this solved?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 15:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290340#M7758</guid>
      <dc:creator>randy_moore</dc:creator>
      <dc:date>2018-06-15T15:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: How can I audit changes made to Splunk Role Index access?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290341#M7759</link>
      <description>&lt;P&gt;Yes, I am good to go on this one.  Thank you for the follow-up!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:57:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290341#M7759</guid>
      <dc:creator>nthornbury</dc:creator>
      <dc:date>2018-06-18T13:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: How can I audit changes made to Splunk Role Index access?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290342#M7760</link>
      <description>&lt;P&gt;Problem Solved.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:57:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290342#M7760</guid>
      <dc:creator>nthornbury</dc:creator>
      <dc:date>2018-06-18T13:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: How can I audit changes made to Splunk Role Index access?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290343#M7761</link>
      <description>&lt;P&gt;Would you be so kind and share how you solved it, so that others can benefit from the info. &lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 08:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290343#M7761</guid>
      <dc:creator>peter_krammer</dc:creator>
      <dc:date>2018-08-13T08:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can I audit changes made to Splunk Role Index access?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290344#M7762</link>
      <description>&lt;P&gt;Peter,&lt;/P&gt;

&lt;P&gt;I developed a report that runs each week, and sends me the reults fo the following search string:&lt;/P&gt;

&lt;P&gt;index=_audit source=audittrail operation=edit action!=search action=edit_roles&lt;/P&gt;

&lt;P&gt;You could modify this search with other parameters that suit your particular needs or frequency.  The above, will show you all mods made to the admin role.  I hope that helps.  Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:51:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-audit-changes-made-to-Splunk-Role-Index-access/m-p/290344#M7762</guid>
      <dc:creator>nthornbury</dc:creator>
      <dc:date>2020-09-29T20:51:10Z</dc:date>
    </item>
  </channel>
</rss>

