All Apps and Add-ons

Any App to audit changes in Splunk Enterprise distributed environment ?

neerajs_81
Builder

Hi, is there any app similar to https://splunkbase.splunk.com/app/4144/ for auditing changes made to different settings, conf files in a Clustered deployment ?  If there is NO app, can someone recommend a report that can be run ?

Any help appreciated. 


Labels (2)
Tags (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@neerajs_81 - Try this App for configuration changes monitoring. (I've not tried it personally but it sounds promising.)

Git Version Control App for Splunk -  https://splunkbase.splunk.com/app/4182/

 

You can search through splunkd_access logs, it will give you what component changed, and who changed it but will not tell the old value and new value.

index="_internal" sourcetype="splunkd_access"

 

I hope this helps!!

View solution in original post

gjanders
SplunkTrust
SplunkTrust

Also refer to previous answers https://community.splunk.com/t5/Dashboards-Visualizations/Version-control-management-for-Splunk-Dash...

 

Version control for splunk also does this among other options...the knowledge object overview app on SplunkBase has some queries for this too. https://splunkbase.splunk.com/app/5399/

neerajs_81
Builder

Thank you

0 Karma

neerajs_81
Builder

Thank you, checking it out.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@neerajs_81 - Try this App for configuration changes monitoring. (I've not tried it personally but it sounds promising.)

Git Version Control App for Splunk -  https://splunkbase.splunk.com/app/4182/

 

You can search through splunkd_access logs, it will give you what component changed, and who changed it but will not tell the old value and new value.

index="_internal" sourcetype="splunkd_access"

 

I hope this helps!!

Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...