Monitoring Splunk

How to audit changes in Splunk objects (Git or else)?

evelenke
Contributor

Hi Splunkers,

we need to monitor who, when, where and what was changed in macros, searches and so on.

Internal index can answer to "who, when, where" (audit POST requests). 

Which is the right and preferred way to answer to "what" exactly was added or removed to/from the knowledge object during the change operation.

P.S. We have to have this information in Splunk and correlate with _internal audit

Labels (2)
0 Karma

jcaceres
Explorer

Take a look at Splunk Ideas E-I-49  and upvote. I think that aligns with what you're looking for. 

0 Karma

shivanshu1593
Builder

You may want to look into this, as it looks somewhat similar to your requirements. Mind you, there are going to be a lot of false positives.

How to audit changes in savedsearches.conf 

Hope this helps,

S

 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

evelenke
Contributor

Hi,

so you say "_audit index is your friend for this" , but in the answer you'd proposed me the very first sentence is "It's already been determined that alarms/reports modifications are not being audited in _audit and _internal indexes." . 🙂

Thanks anyway!

0 Karma

shivanshu1593
Builder

Ah my bad. First started  with the audit index, then remembered that a thread is already there for the issue. Totally forgot to edit the post after pasting the link.

Thanks for pointing out, man 😄

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...