Alerting

Alert for deletion/change of knowledge objects

NatWong
Explorer

Hi All,

How do I create an alert when user=admin delete/change any knowledge object.

The background is all security alerts are created using admin and we need to be alerted when those security alerts (reports , alerts ) are changed or deleted.

Regard,
N

Tags (1)
0 Karma

FrankVl
Ultra Champion

I'd expect that to be visible in _audit index. Just try creating one and changing / deleting it, to see what it looks like in _audit, so you can build some alerts on that.

Edit:
Had a quick look at it and cannot find obvious traces in _audit. _internal does show some clues though, events with method=POST for changes of reports/alerts and events with method=DELETE for deletes of alerts/reports.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...