<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we audit Hunk's users? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324957#M2986</link>
    <description>&lt;P&gt;Much appreciated!!!&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2017 00:43:25 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2017-04-12T00:43:25Z</dc:date>
    <item>
      <title>How can we audit Hunk's users?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324955#M2984</link>
      <description>&lt;P&gt;We would like to audit the Hunk's users. Meaning, which users use the system, when, how much... we are on Hunk version 6.5.2.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 20:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324955#M2984</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-04-11T20:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: How can we audit Hunk's users?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324956#M2985</link>
      <description>&lt;P&gt;To audit all the users who log into the Hunk Search Head, see this answer: &lt;A href="https://answers.splunk.com/answers/225682/how-to-search-splunks-internal-audit-events-to-see.html"&gt;https://answers.splunk.com/answers/225682/how-to-search-splunks-internal-audit-events-to-see.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;From a Hadoop point of view, all of Splunk Users run the MapReduce job as the user who installed Splunk, so that should be in the Hadoop log.  You can use this Splunk App to log the Hadoop logs: &lt;A href="https://splunkbase.splunk.com/app/3134/"&gt;https://splunkbase.splunk.com/app/3134/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 23:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324956#M2985</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2017-04-11T23:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can we audit Hunk's users?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324957#M2986</link>
      <description>&lt;P&gt;Much appreciated!!!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 00:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-we-audit-Hunk-s-users/m-p/324957#M2986</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-04-12T00:43:25Z</dc:date>
    </item>
  </channel>
</rss>

