We are trying to audit/monitor administrative activity to Splunk. Is there some canned dashboards or searches that can be used to monitor/review elevated privilege activity? How do we monitor change management on Splunk itself?
Hi @spctravis,
you should see the following apps:
where you can find many pre built dashboards for Splunk users auditing.
If there aren't the Use Cases you want, you can find some useful starting point to create your own dashboards.
Ciao.
Giuseppe
Hi @spctravis,
you should see the following apps:
where you can find many pre built dashboards for Splunk users auditing.
If there aren't the Use Cases you want, you can find some useful starting point to create your own dashboards.
Ciao.
Giuseppe