Monitoring Splunk

How to monitor Splunk changes?

guarisma
Contributor

Hello,

Looking for a way to monitor certain operational changes in Splunk like:
- A new sourcetype has been created.
- A new Input has been created.
- An input was removed/deleted.
- An Alert or Report was created or deleted.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should use version control for any conf changes made to your indexers, search heads, deployment servers, etc.. You can also leverage the internal log to answer the alert/report modification

index=_audit

0 Karma

guarisma
Contributor

What event will tell me a new index was created in Splunk Cloud?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Yeah, this is available in the audit index too. Please accept the answer if this answered your questions

index=_audit action=indexes_edit

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...