Monitoring Splunk

How o audit Dashboard Inputs?

bred1
New Member

Hi,

I need to be able to see what inputs people are entering into dashboard panels (i.e. what filters they are applying or searching for).

So far I have used the _audit and _internal indexes to be able to see which users have accessed which saved-searches on each dashboard, but have not been able to identify the input that they have entered.

I am hoping to create a dashboard table for this.

Thanks.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Message Parsing in SOCK

Introduction This blog post is part of an ongoing series on SOCK enablement. In this blog post, I will write ...

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...

Use ‘em or lose ‘em | Splunk training units do expire

Whether it’s hummus, a ham sandwich, or a human, almost everything in this world has an expiration date. And, ...