Monitoring Splunk

Splunk Loggin of admin acess

richard_gosling
New Member

We are running a slightly older version of Splunk (4) on Centos 5.5.

I have looked around but was just wondering if the actions taken by an gui admin are logged anywhere.

ie John Smith removed server x from tag list Y?

Tags (3)
0 Karma

ftk
Motivator

You should be able to find all of this information in the _audit index. All actions performed in Splunk are logged there, including admin activity.

index=_audit

For more info and examples, check the docs here: http://docs.splunk.com/Documentation/Splunk/latest/Security/AuditSplunkactivity

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...