Archive
Highlighted

How to monitor Splunk changes?

Communicator

Hello,

Looking for a way to monitor certain operational changes in Splunk like:
- A new sourcetype has been created.
- A new Input has been created.
- An input was removed/deleted.
- An Alert or Report was created or deleted.

0 Karma
Highlighted

Re: How to monitor Splunk changes?

SplunkTrust
SplunkTrust

You should use version control for any conf changes made to your indexers, search heads, deployment servers, etc.. You can also leverage the internal log to answer the alert/report modification

index=_audit

0 Karma
Highlighted

Re: How to monitor Splunk changes?

Communicator

What event will tell me a new index was created in Splunk Cloud?

0 Karma
Highlighted

Re: How to monitor Splunk changes?

SplunkTrust
SplunkTrust

Yeah, this is available in the audit index too. Please accept the answer if this answered your questions

index=audit action=indexesedit

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.