Security

how can i see who has run queries or dashboards

vincenp2
New Member

Is there an easy way to work out who has run queries or dashboards on Splunk and obtain contact information e.g. e-mail addresses

we are moving from one splunk environment to another, and would like to be able to identify users still using the old environment, and what they are accessing.

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

Use the audit index.

index=_audit action=search user=*
0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...