Monitoring Splunk

How to monitor Splunk changes?

guarisma
Contributor

Hello,

Looking for a way to monitor certain operational changes in Splunk like:
- A new sourcetype has been created.
- A new Input has been created.
- An input was removed/deleted.
- An Alert or Report was created or deleted.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should use version control for any conf changes made to your indexers, search heads, deployment servers, etc.. You can also leverage the internal log to answer the alert/report modification

index=_audit

0 Karma

guarisma
Contributor

What event will tell me a new index was created in Splunk Cloud?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Yeah, this is available in the audit index too. Please accept the answer if this answered your questions

index=_audit action=indexes_edit

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...