Monitoring Splunk

Lookup CSV updates for a audit purpose?

joomla
Engager

Hi Team,

Can we monitor the lookup files i.e from updates prospective who updates what in a lookup file or even in a KV store. This is one of the requirements of monitoring so that if tomorrow something needed; we can backtrack and able to answer who; what and when.

Thanks in advance.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I don't think this is tracked by Splunk - How are you updating the csv store? If you are using a search, you could update the csv to include a field with the user who updated it, or you could restrict the update process so that only certain users could perform the update.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...