Getting Data In

Is there a way to monitor Splunk knowledge object permissions?

adityapavan18
Contributor

I am trying to generate report daily to monitor changes in knowledge objects (changes in permissions/new artifacts created/deleted/edited so on...) in Splunk. Is there any place they will be logged?

0 Karma

woodcock
Esteemed Legend

You can get a list of all the KOs you care about like this:

|rest/services/configs/conf-macros | eval config="macros" | append [|rest/services/configs/conf-lookups | eval config="lookups"] | append ...

Then you can examine the permission fields you care about and export them to a file with outputlookup. Run this search every day and schedule another search to run just before you overwrite it, that checks the values now and look for differences.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...