<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to audit changes in Splunk objects (Git or else)? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/513815#M4411</link>
    <description>&lt;P&gt;You may want to look into this, as it looks somewhat similar to your requirements. Mind you, there are going to be a lot of false positives.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Monitoring-Splunk/A-way-to-audit-changes-to-savedsearches-conf/td-p/511888" target="_self"&gt;How to audit changes in savedsearches.conf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Aug 2020 10:25:51 GMT</pubDate>
    <dc:creator>shivanshu1593</dc:creator>
    <dc:date>2020-08-14T10:25:51Z</dc:date>
    <item>
      <title>How to audit changes in Splunk objects (Git or else)?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/513267#M4401</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;we need to monitor who, when, where and what was changed in macros, searches and so on.&lt;/P&gt;&lt;P&gt;Internal index can answer to "who, when, where" (audit POST requests).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is the right and preferred way to answer to "what" exactly was added or removed to/from the knowledge object during the change operation.&lt;/P&gt;&lt;P&gt;P.S. We have to have this information in Splunk and correlate with _internal audit&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 08:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/513267#M4401</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2020-08-10T08:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to audit changes in Splunk objects (Git or else)?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/513815#M4411</link>
      <description>&lt;P&gt;You may want to look into this, as it looks somewhat similar to your requirements. Mind you, there are going to be a lot of false positives.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Monitoring-Splunk/A-way-to-audit-changes-to-savedsearches-conf/td-p/511888" target="_self"&gt;How to audit changes in savedsearches.conf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 10:25:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/513815#M4411</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-08-14T10:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to audit changes in Splunk objects (Git or else)?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/514063#M4414</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;so you say "&lt;SPAN&gt;_audit index is your friend for this"&lt;/SPAN&gt; , but in the answer you'd proposed me the very first sentence is "&lt;SPAN&gt;It's already been determined that alarms/reports modifications are not being audited in _audit and _internal indexes." . &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks anyway!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 09:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/514063#M4414</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2020-08-14T09:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to audit changes in Splunk objects (Git or else)?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/514064#M4415</link>
      <description>&lt;P&gt;Ah my bad. First started&amp;nbsp; with the audit index, then remembered that a thread is already there for the issue. Totally forgot to edit the post after pasting the link.&lt;/P&gt;&lt;P&gt;Thanks for pointing out, man &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 10:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/514064#M4415</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-08-14T10:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to audit changes in Splunk objects (Git or else)?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/516613#M4432</link>
      <description>&lt;P&gt;Take a look at &lt;A title="Better audit logs suggested in Ideas" href="https://ideas.splunk.com/ideas/E-I-49" target="_blank" rel="noopener"&gt;Splunk Ideas E-I-49&lt;/A&gt;&amp;nbsp; and upvote. I think that aligns with what you're looking for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 00:23:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-audit-changes-in-Splunk-objects-Git-or-else/m-p/516613#M4432</guid>
      <dc:creator>jcaceres</dc:creator>
      <dc:date>2020-08-28T00:23:37Z</dc:date>
    </item>
  </channel>
</rss>

