Monitoring Splunk

Splunk Loggin of admin acess

richard_gosling
New Member

We are running a slightly older version of Splunk (4) on Centos 5.5.

I have looked around but was just wondering if the actions taken by an gui admin are logged anywhere.

ie John Smith removed server x from tag list Y?

Tags (3)
0 Karma

ftk
Motivator

You should be able to find all of this information in the _audit index. All actions performed in Splunk are logged there, including admin activity.

index=_audit

For more info and examples, check the docs here: http://docs.splunk.com/Documentation/Splunk/latest/Security/AuditSplunkactivity

Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...