<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are the Log channel (found in Server settings/Server logging) documented in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200745#M98727</link>
    <description>&lt;P&gt;Unfortunately not.&lt;/P&gt;

&lt;P&gt;Basically I want to know what, for example, the &lt;STRONG&gt;AuthenticationManagerSplunk&lt;/STRONG&gt; log channel provides when I change it's log level from WARN (it's default) to say INFO (or DEBUG).&lt;/P&gt;

&lt;P&gt;I suppose I could set all the log channels to INFO (or DEBUG) and see what happens, but I was hoping they might be documented.&lt;/P&gt;

&lt;P&gt;Basically, it's good for an application to generate logs, as we all know else we wouldnt be using Splunk :-), but it's great if we can find out what the logs mean or what can be generated.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Dec 2015 10:16:58 GMT</pubDate>
    <dc:creator>burnalting</dc:creator>
    <dc:date>2015-12-24T10:16:58Z</dc:date>
    <item>
      <title>Are the Log channel (found in Server settings/Server logging) documented</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200743#M98725</link>
      <description>&lt;P&gt;I want to see what options I have to log user activity within Splunk.&lt;/P&gt;

&lt;P&gt;Are the Log Channels or the category found in log.cfg documented with respect to what their levels would generate?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 05:04:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200743#M98725</guid>
      <dc:creator>burnalting</dc:creator>
      <dc:date>2015-12-24T05:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Are the Log channel (found in Server settings/Server logging) documented</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200744#M98726</link>
      <description>&lt;P&gt;Take a look at this:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope that helps&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 08:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200744#M98726</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2015-12-24T08:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Are the Log channel (found in Server settings/Server logging) documented</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200745#M98727</link>
      <description>&lt;P&gt;Unfortunately not.&lt;/P&gt;

&lt;P&gt;Basically I want to know what, for example, the &lt;STRONG&gt;AuthenticationManagerSplunk&lt;/STRONG&gt; log channel provides when I change it's log level from WARN (it's default) to say INFO (or DEBUG).&lt;/P&gt;

&lt;P&gt;I suppose I could set all the log channels to INFO (or DEBUG) and see what happens, but I was hoping they might be documented.&lt;/P&gt;

&lt;P&gt;Basically, it's good for an application to generate logs, as we all know else we wouldnt be using Splunk :-), but it's great if we can find out what the logs mean or what can be generated.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 10:16:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200745#M98727</guid>
      <dc:creator>burnalting</dc:creator>
      <dc:date>2015-12-24T10:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: Are the Log channel (found in Server settings/Server logging) documented</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200746#M98728</link>
      <description>&lt;P&gt;There's some documentation about the log.cfg &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Enabledebuglogging"&gt;here&lt;/A&gt; but I don't think that's going to give you enough level of detail.&lt;BR /&gt;
If you don't get any other replies here try opening a support ticket with Splunk and see if that helps.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
J&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 17:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200746#M98728</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2015-12-24T17:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Are the Log channel (found in Server settings/Server logging) documented</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200747#M98729</link>
      <description>&lt;P&gt;The links javiergn posted have a wealth of information. &lt;BR /&gt;
Are you really missing anything in the default log levels - is there something specific you are trying to see? As the documentation says, all user activity is logged.  (see index=_audit). If you're not seeing something it may indicate another problem.&lt;/P&gt;

&lt;P&gt;To familiarise yourself with whats being logged about users you try  the following search &lt;CODE&gt;index=_* user=*&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This should show you all the logs with a user field. You'll see web access logs, audit logs etc. &lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 20:55:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200747#M98729</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2015-12-24T20:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Are the Log channel (found in Server settings/Server logging) documented</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200748#M98730</link>
      <description>&lt;P&gt;Thanks Guys.&lt;/P&gt;

&lt;P&gt;J, I think the support ticket will be the way to go.&lt;/P&gt;

&lt;P&gt;JP, you are correct. The most useful logs for user activity are the returns from&lt;BR /&gt;
 - index=_audit&lt;BR /&gt;
 - index=_internal source="/opt/splunk/var/log/splunk/splunkd_ui_access.log"&lt;BR /&gt;
but I am interested in what additional information that may reveal more information about a user's activity that may be available but is not turned on by default.&lt;BR /&gt;
For example, _audit records a user creating a role (operation=create) and the fact that they have displayed it (operation=list) and updated it (operation=edit) but no information about what was changed when setting up this role. I am interested if one of the log channel 'variables', if set to a higher log level would give me more information about what features were given to the role.&lt;BR /&gt;
Another example just tested, was the changing a user's role from just 'user' to 'admin'. The only logs (given the default posture) indicate the person changed the role of a user, but no details about what role they assigned/de-assigned. Perhaps there is  something I can configure that will have these logs record what actually changed.&lt;BR /&gt;
Also, when I print, there is no log at all yet there is an event if I export a result set directly.&lt;/P&gt;

&lt;P&gt;I am just new to Splunk (one day) but I am reviewing it's ability to record user activity within in. That is,  to record details about &lt;BR /&gt;
 - user and role management&lt;BR /&gt;
 - configuration/data management&lt;BR /&gt;
 - searches (basic, reports, scheduled, etc)&lt;BR /&gt;
 - import and export of data&lt;BR /&gt;
Basically all the fundamentals of protective monitoring.&lt;/P&gt;

&lt;P&gt;My two main explorations are&lt;BR /&gt;
 - what record of activity exists (or can exist) - &lt;EM&gt;my main challenge so far&lt;/EM&gt;&lt;BR /&gt;
 - how to gain that record of activity in order to send it to a non reputable store - &lt;EM&gt;this appears easy with splunk&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-the-Log-channel-found-in-Server-settings-Server-logging/m-p/200748#M98730</guid>
      <dc:creator>burnalting</dc:creator>
      <dc:date>2020-09-29T08:13:08Z</dc:date>
    </item>
  </channel>
</rss>

