Monitoring Splunk

Lookup CSV updates for a audit purpose?

joomla
Engager

Hi Team,

Can we monitor the lookup files i.e from updates prospective who updates what in a lookup file or even in a KV store. This is one of the requirements of monitoring so that if tomorrow something needed; we can backtrack and able to answer who; what and when.

Thanks in advance.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I don't think this is tracked by Splunk - How are you updating the csv store? If you are using a search, you could update the csv to include a field with the user who updated it, or you could restrict the update process so that only certain users could perform the update.

0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...