Getting Data In

How do you audit for who is disabling Data Input?

kennethyeung
New Member

Recently, we found one data input for receiving syslog was stopped.

We don't know if the service issue is auto stop or someone disabling it. i tried to search index=_audit,

Also, I even saw some log edit server, only see the action is edit server but it didn't mention what setting had been changed.

0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...