Getting Data In

Splunk 5.0.5, Does Splunk logs object deletion activity from Splunk Web ?

somesoni2
SplunkTrust
SplunkTrust

Hi,

We have a shared development environment for Splunk (version 5.0.5) where many users do create/updated/delete Splunk objects (e.g. saved searches/views/lookups etc).

Does Splunk logs any information in any internal logs for who created (not imp at this point)/deleted (this is what I want to know for sure)/updated any of the objects? Something like auditing Splunk Web activities.

Appreciate your help.

Tags (2)
1 Solution

rahulroy_splunk
Path Finder

This seems to be working for deleted items.

index=_internal sourcetype=splunkd_access method="DELETE"

I'm too looking for "UPDATE" but no luck so far.

View solution in original post

rahulroy_splunk
Path Finder

This seems to be working for deleted items.

index=_internal sourcetype=splunkd_access method="DELETE"

I'm too looking for "UPDATE" but no luck so far.

Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...