<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic information about Splunk audit events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673947#M230718</link>
    <description>&lt;P&gt;Hi at all,&lt;/P&gt;&lt;P&gt;I need to create some Correlation Searches on Splunk audit events, but I didn't find any documentation about the events to search, e.g. I don't know how to identify creation of a new role or updates to an existing one, I found only action=edit_roles, but I can only know the associted user and not the changed role.&lt;/P&gt;&lt;P&gt;Can anyone idicate an url to find Splunk audit information?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2024 14:37:04 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-01-11T14:37:04Z</dc:date>
    <item>
      <title>information about Splunk audit events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673947#M230718</link>
      <description>&lt;P&gt;Hi at all,&lt;/P&gt;&lt;P&gt;I need to create some Correlation Searches on Splunk audit events, but I didn't find any documentation about the events to search, e.g. I don't know how to identify creation of a new role or updates to an existing one, I found only action=edit_roles, but I can only know the associted user and not the changed role.&lt;/P&gt;&lt;P&gt;Can anyone idicate an url to find Splunk audit information?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 14:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673947#M230718</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-11T14:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: information about Splunk audit events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673954#M230719</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;maybe the _configtracker index can help. It would have old and new values for all configuration changes including changes made to user roles.&lt;/P&gt;&lt;P&gt;BR!&lt;/P&gt;&lt;P&gt;Gunnar&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 15:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673954#M230719</guid>
      <dc:creator>Gunnar</dc:creator>
      <dc:date>2024-01-11T15:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: information about Splunk audit events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673957#M230720</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223081"&gt;@Gunnar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thank you for your hint, in the&amp;nbsp;&lt;SPAN&gt;_configtracker&amp;nbsp;index there isn't any information about the user who did a change, and anyway isn't so well documented: I should search to understand events by myself, I'm searching for a documentation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 15:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/information-about-Splunk-audit-events/m-p/673957#M230720</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-11T15:56:56Z</dc:date>
    </item>
  </channel>
</rss>

