All Apps and Add-ons

How to audit all privileged user (admin) actions within our domain?

New Member


I want to be able to audit all privileged users within our domain i.e. elevated privileges, install apps, remove files, etc. I noticed there was something called the Splunk App for PCI Compliance - Splunk Enterprise that had an audit privilege user actions function, and wanted to know if that was applicable to domain admins. I've tried searching with index=_audit user=admin action=edit_user, however, it does not return enough information and only seems to return information about Splunk. Thanks.

0 Karma


To clarify, yes the _audit index is for storing audit events related to Splunk itself. Most apps have a way of auditing activity, and that is Splunk's. It won't contain audit data for the rest of your infrastructure/apps.

The PCI app, I believe, is designed to help you meet PCI Compliance (think credit card payments). So I doubt it will help you audit the rest of your infrastructure (but I don't have it installed so can't speak to it much beyond that). From the description of the app

The Splunk App for PCI Compliance (for Splunk Enterprise) is a Splunk developed and supported App designed to help organizations meet PCI DSS requirements. It reviews and measures the effectiveness and status of PCI compliance technical controls in real time. It can also identify and prioritize any control areas that may need to be addressed and let you quickly address any auditor report or data request.

For your use case, it might help to define what you mean by "audit all privileged users". Audit their logins? Audit their actions? Password Changes? Etc? Once you know what you're looking to audit, determine where that audit data exists - app logs, win event logs, databases etc. Then ingest those data sources into Splunk. Once the data is in Splunk, then you can run searches across that data to help audit whatever events you identified in step 1.

I know that's a very generic answer, but it was a pretty broad question too. Hope it helps a little at least.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...