Dashboards & Visualizations

Is there an app or search for dashboards and alerts to track activity of Splunk users with ADMIN roles?

atx876
Explorer

We have quite a few users with Splunk "Admin" roles. Is there a way to create a dashboards/alerts when splunk users with ADMIN role logs in? In other words, is there an app or search to track Splunk users with ADMIN privileges? We are using local Splunk authentication.

jimodonald
Contributor

I'm not aware of an app for that, but you should be able to roll your own.

Here is a search for all your admin users:

| rest /services/authentication/users | where roles="admin" | dedup title | table title, roles, realname

You should then be able to take that small list as a filter for index=_audit.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...