<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to explain follow _audit log? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-explain-follow-audit-log/m-p/610459#M212302</link>
    <description>&lt;P&gt;&lt;SPAN class=""&gt;I found follow logs in _audit logs.&amp;nbsp; The user who run this search cannot access internal logs, so I assume the underline part is added by Splunk system.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Could anyboda explain follow 2 questions?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;What does the underline part mean? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;what does the field _cd mean?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;search=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;search&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;index=&lt;/SPAN&gt;&lt;SPAN&gt;* &lt;/SPAN&gt;&lt;SPAN class=""&gt;OR&lt;/SPAN&gt; &lt;SPAN class=""&gt;index=_&lt;/SPAN&gt;&lt;SPAN&gt;*) &lt;/SPAN&gt;&lt;SPAN class=""&gt;_time&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;=1661000447&lt;/SPAN&gt; &lt;SPAN class=""&gt;_time&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;1661000460&lt;/SPAN&gt; &lt;SPAN class=""&gt;host=&lt;/SPAN&gt;&lt;SPAN&gt;"XXX&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;source=&lt;/SPAN&gt;&lt;SPAN&gt;"XXX&lt;/SPAN&gt;&lt;SPAN&gt;" | &lt;/SPAN&gt;&lt;U&gt;&lt;SPAN class=""&gt;eval&lt;/SPAN&gt; &lt;SPAN class=""&gt;_DBID&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt; &lt;SPAN class=""&gt;replace&lt;/SPAN&gt;(&lt;SPAN class=""&gt;_cd&lt;/SPAN&gt;, "(&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;+)&lt;SPAN class=""&gt;:\d&lt;/SPAN&gt;+", "&lt;SPAN class=""&gt;\1&lt;/SPAN&gt;") | &lt;SPAN class=""&gt;eval&lt;/SPAN&gt; &lt;SPAN class=""&gt;_OFFSET&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt; &lt;SPAN class=""&gt;replace&lt;/SPAN&gt;(&lt;SPAN class=""&gt;_cd&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;+&lt;SPAN class=""&gt;:&lt;/SPAN&gt;(&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;+)", "&lt;SPAN class=""&gt;\1&lt;/SPAN&gt;")']&lt;/U&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 07:40:35 GMT</pubDate>
    <dc:creator>xiyangyang</dc:creator>
    <dc:date>2022-08-23T07:40:35Z</dc:date>
    <item>
      <title>How to explain follow _audit log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-explain-follow-audit-log/m-p/610459#M212302</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;I found follow logs in _audit logs.&amp;nbsp; The user who run this search cannot access internal logs, so I assume the underline part is added by Splunk system.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Could anyboda explain follow 2 questions?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;What does the underline part mean? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;what does the field _cd mean?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;search=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;search&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;index=&lt;/SPAN&gt;&lt;SPAN&gt;* &lt;/SPAN&gt;&lt;SPAN class=""&gt;OR&lt;/SPAN&gt; &lt;SPAN class=""&gt;index=_&lt;/SPAN&gt;&lt;SPAN&gt;*) &lt;/SPAN&gt;&lt;SPAN class=""&gt;_time&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;=1661000447&lt;/SPAN&gt; &lt;SPAN class=""&gt;_time&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;1661000460&lt;/SPAN&gt; &lt;SPAN class=""&gt;host=&lt;/SPAN&gt;&lt;SPAN&gt;"XXX&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;source=&lt;/SPAN&gt;&lt;SPAN&gt;"XXX&lt;/SPAN&gt;&lt;SPAN&gt;" | &lt;/SPAN&gt;&lt;U&gt;&lt;SPAN class=""&gt;eval&lt;/SPAN&gt; &lt;SPAN class=""&gt;_DBID&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt; &lt;SPAN class=""&gt;replace&lt;/SPAN&gt;(&lt;SPAN class=""&gt;_cd&lt;/SPAN&gt;, "(&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;+)&lt;SPAN class=""&gt;:\d&lt;/SPAN&gt;+", "&lt;SPAN class=""&gt;\1&lt;/SPAN&gt;") | &lt;SPAN class=""&gt;eval&lt;/SPAN&gt; &lt;SPAN class=""&gt;_OFFSET&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt; &lt;SPAN class=""&gt;replace&lt;/SPAN&gt;(&lt;SPAN class=""&gt;_cd&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;+&lt;SPAN class=""&gt;:&lt;/SPAN&gt;(&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;+)", "&lt;SPAN class=""&gt;\1&lt;/SPAN&gt;")']&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 07:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-explain-follow-audit-log/m-p/610459#M212302</guid>
      <dc:creator>xiyangyang</dc:creator>
      <dc:date>2022-08-23T07:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to explain follow _audit log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-explain-follow-audit-log/m-p/610476#M212312</link>
      <description>&lt;P&gt;The underscore in an index or field name is just part of the name, however, names beginning with an underscore are reserved for use by Splunk.&lt;/P&gt;&lt;P&gt;The _cd field gives the location of an event within an index.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2203/Knowledge/Usedefaultfields#_cd" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2203/Knowledge/Usedefaultfields#_cd&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 12:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-explain-follow-audit-log/m-p/610476#M212312</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-23T12:09:29Z</dc:date>
    </item>
  </channel>
</rss>

