Dashboards & Visualizations

Is there an app or search for dashboards and alerts to track activity of Splunk users with ADMIN roles?

atx876
Explorer

We have quite a few users with Splunk "Admin" roles. Is there a way to create a dashboards/alerts when splunk users with ADMIN role logs in? In other words, is there an app or search to track Splunk users with ADMIN privileges? We are using local Splunk authentication.

jimodonald
Contributor

I'm not aware of an app for that, but you should be able to roll your own.

Here is a search for all your admin users:

| rest /services/authentication/users | where roles="admin" | dedup title | table title, roles, realname

You should then be able to take that small list as a filter for index=_audit.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...