Dashboards & Visualizations

How can I see who viewed the results in a dashboard or search?

New Member

How can I see who viewed the results in a dashboard or search? I need to know what weblog or audit log info would look like when a user views the results of a search.

0 Karma


Rather than hand you a fish, I'm going to teach you how to catch this particular type. (Or any particular type of fish, by varying the bait you use.)

First, go look at the dashboard yourself and run that search. Now you know one person who has done so, and you know exactly what time they did and what their user id is, because it's you, and you did it just now.

Second, wait for about five minutes. This lag is so that when you start searching, your new searches that have some of the same key words that you are looking for will not show up in your results.

Third, go look at index=_audit for your userid in a fixed date and time range at that exact time plus a minute before and a minute after. Chances are pretty good, you'll see the exact record you were looking for. If not, then search for your IP address at that time, or look for the name of the saved search that the dashboard runs, or if there is no name for that search in the dash, then look for some of the specific SPL that is executed.

Once you know how to catch the fish you just threw in, widen your net and look for at least one more fish of the same type. That proves you haven't tightened your requirements too much.

Any of the above steps will help you find the records in the wild that match the tame fish that you threw in for practice.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...