<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User audit report in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152983#M3400</link>
    <description>&lt;P&gt;You may want to look at the reports provided by SOS (splunk-on-splunk) app. They have reports with data like "UI Search Activity by User","Recent Usage by User (Non-Scheduled Only)"&lt;/P&gt;</description>
    <pubDate>Mon, 05 May 2014 21:45:32 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-05-05T21:45:32Z</dc:date>
    <item>
      <title>User audit report</title>
      <link>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152981#M3398</link>
      <description>&lt;P&gt;Hello, I am enhancing an existing Splunk instance and I want to build or find a report that will tell me who accessed the system and when, and what searches or reports they ran.  Is there a canned report that will tell me this information?  If not, can someone help me define the search to turn up this information?  Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 18:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152981#M3398</guid>
      <dc:creator>mcrouse</dc:creator>
      <dc:date>2014-05-05T18:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: User audit report</title>
      <link>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152982#M3399</link>
      <description>&lt;P&gt;This may be close to what you want:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit action=search search=* NOT "typeahead" NOT metadata NOT "|history" NOT "AUTOSUMMARY" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You may want to play around with it to include/eliminate certain searches.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 19:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152982#M3399</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-05-05T19:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: User audit report</title>
      <link>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152983#M3400</link>
      <description>&lt;P&gt;You may want to look at the reports provided by SOS (splunk-on-splunk) app. They have reports with data like "UI Search Activity by User","Recent Usage by User (Non-Scheduled Only)"&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 21:45:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152983#M3400</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-05-05T21:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: User audit report</title>
      <link>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152984#M3401</link>
      <description>&lt;P&gt;Hi Iguinn. Its a good answer. Could you please explain you have eliminated few words like typeahead metadata history and autosummary. I am able see the differences but am not able to understand the exact purpose&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 12:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-audit-report/m-p/152984#M3401</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2016-06-23T12:31:28Z</dc:date>
    </item>
  </channel>
</rss>

