Archive
Highlighted

Audit knowledge object usage

Loves-to-Learn Lots

Hello,

I'm trying to audit knowledge object usage. Is there really no way to log when a knowledge object is called?

Thanks and Regards.

Tags (1)
0 Karma
Highlighted

Re: Audit knowledge object usage

SplunkTrust
SplunkTrust

well, the answer for your questions is: "it depends" but probably couple of them
it depends on the knowledge objects you are after, for example, you can find the use of lookups in a pretty straight forward way ... look for all your lookup via | rest find if they are used in a search / saved something pretty much by lookup for searches that have the command | lookup or | inputlookup or | ouputlookup
as for tags, eventtypes, fields and other, it might be a little more complex.
my approach will be to find the searches you use by a sourcetype as your knowledge object should always be tied to one. if there are sourcetypes you arent using,
lastly, worthwhile to distinguish between index time and search time knowledge object which is not always an easy task ...

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.