Hello,
Does anyone know if there's a way to monitor/track API calls to a Splunk Cloud instance? Looking particularly for the IP and user account being used for the API call to the cloud instance. I've done some searching and came up empty.
Thanks.
Not 100% sure, but that should be in one of the *_access logs in index=_internal.
Not 100% sure, but that should be in one of the *_access logs in index=_internal.
thank you, that pointed me in the right direction.