Getting Data In

_audit log keeps track of over a million actions daily, but does it audit export (e.g. CSV) and share?

greich
Communicator

Sharing a search, which makes the results public if I am not mistaken, and exports e.g. to CSV seem two security risks.
I cannot find an action/capability under which it is recorded in the audit log.

Tags (3)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

Not in the audit log, but this is tracked in the web access log. Try doing a search for export in _internal to find exports. Sharing is a bit more complicated, but the UI will hit the acl endpoint to adjust the permissions, which effectively shares it (though it doesn't tell you that the user actually sent out the link, or tell you that anyone looked at it).

Alternatively, you can leverage the app that I wrote to track exactly these types of questions. The app is called Search Activity, and is here: https://apps.splunk.com/app/2632/. The app tracks all of the above in an accelerated data store (allowing you to query those millions of messages over months in a fraction of a second), and I'm also going to create a method in an upcoming release to allow you to find when multiple users view the same search results -- I.e., not just that I shared my results but that you actually viewed them.

View solution in original post

David
Splunk Employee
Splunk Employee

Not in the audit log, but this is tracked in the web access log. Try doing a search for export in _internal to find exports. Sharing is a bit more complicated, but the UI will hit the acl endpoint to adjust the permissions, which effectively shares it (though it doesn't tell you that the user actually sent out the link, or tell you that anyone looked at it).

Alternatively, you can leverage the app that I wrote to track exactly these types of questions. The app is called Search Activity, and is here: https://apps.splunk.com/app/2632/. The app tracks all of the above in an accelerated data store (allowing you to query those millions of messages over months in a fraction of a second), and I'm also going to create a method in an upcoming release to allow you to find when multiple users view the same search results -- I.e., not just that I shared my results but that you actually viewed them.

greich
Communicator

The app looks interesting, and I will follow up on this.
In the meanwhile, accepting this answer as the hint was relevant and allowed me to complete the immediate stats gathering exercise.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...