<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk query to check which user disabled/enabled alert. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588057#M204801</link>
    <description>&lt;P&gt;Thanks for the response.&amp;nbsp; What I am trying to do is to see when a rule has been enabled\disabled and by who.&amp;nbsp; I Your suggestion will give me who has disabled\enabled but I am trying to figure out what was enabled\disabled... BUT I am closer thanks to you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 15:45:00 GMT</pubDate>
    <dc:creator>cmeisch</dc:creator>
    <dc:date>2022-03-08T15:45:00Z</dc:date>
    <item>
      <title>How to create a search to check which user disabled/enabled alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453190#M173150</link>
      <description>&lt;P&gt;Splunk query to check which user disabled/enabled alert.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 17:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453190#M173150</guid>
      <dc:creator>AnmolKohli</dc:creator>
      <dc:date>2022-03-08T17:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453191#M173151</link>
      <description>&lt;P&gt;Care to elaborate?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 15:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453191#M173151</guid>
      <dc:creator>ccl0utier</dc:creator>
      <dc:date>2019-02-05T15:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453192#M173152</link>
      <description>&lt;P&gt;We have a report built in splunk that runs whenever any alert is disabled by a user in splunk. I want to find the user who has disabled the alert.Is this doable?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 15:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453192#M173152</guid>
      <dc:creator>AnmolKohli</dc:creator>
      <dc:date>2019-02-05T15:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453193#M173153</link>
      <description>&lt;P&gt;See what is in the logs like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit "disabled alert name here"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 05 Feb 2019 16:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/453193#M173153</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-05T16:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/526165#M173154</link>
      <description>&lt;P&gt;not sure&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt;&amp;nbsp;if the new version updated the audit log formats/my old 7.3 does not have yet your search query format,.. but i created a test alert and disabled and queried the audit index, but no match. something fishy.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 04:20:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/526165#M173154</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-23T04:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588040#M204798</link>
      <description>&lt;P&gt;Has this been answered... I am looking for the same thing as to WHO has done what?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 14:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588040#M204798</guid>
      <dc:creator>cmeisch</dc:creator>
      <dc:date>2022-03-08T14:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588051#M204800</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/138653"&gt;@cmeisch&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;you can with following query&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;index="_internal" sourcetype="splunkd_ui_access" file IN (disable,enable)&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;i tried enable/disbale one of saved&amp;nbsp; it , enable disable logs are showing with username who did that action&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SanjayReddy_0-1646753164131.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18363i9BD029685588C585/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SanjayReddy_0-1646753164131.png" alt="SanjayReddy_0-1646753164131.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588051#M204800</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-03-08T15:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588057#M204801</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp; What I am trying to do is to see when a rule has been enabled\disabled and by who.&amp;nbsp; I Your suggestion will give me who has disabled\enabled but I am trying to figure out what was enabled\disabled... BUT I am closer thanks to you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588057#M204801</guid>
      <dc:creator>cmeisch</dc:creator>
      <dc:date>2022-03-08T15:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588059#M204802</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/138653"&gt;@cmeisch&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;index="_internal" sourcetype="splunkd_ui_access" file IN (disable,enable)&lt;BR /&gt;| table _time user uri file&lt;BR /&gt;&lt;BR /&gt;I am not good at regex&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;, but hightlited&amp;nbsp; the savedsearch name on which action done ,&amp;nbsp;&lt;BR /&gt;after &lt;STRONG&gt;searches/&lt;/STRONG&gt; word is the &lt;STRONG&gt;report/alert name&lt;/STRONG&gt; followed by action&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SanjayReddy_0-1646754361992.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18365i391162C7A991F351/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SanjayReddy_0-1646754361992.png" alt="SanjayReddy_0-1646754361992.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;---&lt;BR /&gt;If this reply helps you, an upvote/Karma would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:55:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/588059#M204802</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-03-08T15:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to check which user disabled/enabled alert.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/650415#M224854</link>
      <description>&lt;P&gt;Oh my god finally, someone found it.&amp;nbsp; Here is a revised query that works a little better and shows the "files" (searches) enabled by a particular user and decodes them to make them easier to read.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index="_internal" sourcetype=splunkd_ui_access method=POST&lt;BR /&gt;| eval file=urldecode(file)&lt;BR /&gt;| stats values(file) by user&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 15:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-search-to-check-which-user-disabled-enabled/m-p/650415#M224854</guid>
      <dc:creator>not_for_sale_b</dc:creator>
      <dc:date>2023-07-13T15:36:13Z</dc:date>
    </item>
  </channel>
</rss>

