Monitoring Splunk

How to audit/monitor administrative activity to Splunk?

spctravis
Explorer

We are trying to audit/monitor administrative activity to Splunk.  Is there some canned dashboards or searches that can be used to monitor/review elevated privilege activity?  How do we monitor change management on Splunk itself?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @spctravis,

you should see the following apps:

where you can find many pre built dashboards for Splunk users auditing.

If there aren't the Use Cases you want, you can find some useful starting point to create your own dashboards.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @spctravis,

you should see the following apps:

where you can find many pre built dashboards for Splunk users auditing.

If there aren't the Use Cases you want, you can find some useful starting point to create your own dashboards.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...