All Apps and Add-ons

How to get the history of modifications made to a lookup file?

akarivaratharaj
Communicator

I have gone through a few questions which are related to lookup file changes. I tried to use the same query to get the internal logs regarding my lookup file changes but I am unable to fetch any logs.

I would like to know where can I find the information about the changes made to my lookup file. The information is more related to the user who modified and the respective time.

I tried to search in _audit index, but I am unable to find the exact logs (may be the way of my searching is wrong)

Could anyone please help me in finding the history of modification/changes made to any lookup file?

Labels (1)
Tags (1)
0 Karma

akarivaratharaj
Communicator

Could anyone help me on this please?

0 Karma

akarivaratharaj
Communicator

I am looking this information to check the history of the modification made to a lookup file. If anyone can help me on this, it will be much appreciated!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...