Dashboards & Visualizations

How can I see who viewed the results in a dashboard or search?

dcrooks_cbp
New Member

How can I see who viewed the results in a dashboard or search? I need to know what weblog or audit log info would look like when a user views the results of a search.

0 Karma

DalJeanis
Legend

Rather than hand you a fish, I'm going to teach you how to catch this particular type. (Or any particular type of fish, by varying the bait you use.)

First, go look at the dashboard yourself and run that search. Now you know one person who has done so, and you know exactly what time they did and what their user id is, because it's you, and you did it just now.

Second, wait for about five minutes. This lag is so that when you start searching, your new searches that have some of the same key words that you are looking for will not show up in your results.

Third, go look at index=_audit for your userid in a fixed date and time range at that exact time plus a minute before and a minute after. Chances are pretty good, you'll see the exact record you were looking for. If not, then search for your IP address at that time, or look for the name of the saved search that the dashboard runs, or if there is no name for that search in the dash, then look for some of the specific SPL that is executed.

Once you know how to catch the fish you just threw in, widen your net and look for at least one more fish of the same type. That proves you haven't tightened your requirements too much.

Any of the above steps will help you find the records in the wild that match the tame fish that you threw in for practice.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...