Monitoring Splunk

Which sourcetype to use in order to track changes made to lookup tables?

jsven7
Communicator

SITUATION

  • I'd like to track the changes done to lookup tables.
  • I observe this helpful post: "https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-the-Audit-for-Lookup-files-modificat..."
  • I observe the below sourcetypes having "Lookup edited successfully"
    • lookup_editor_rest_handler
    • lookup_editor_controller
  • I observe both having "Lookup edited successfully"
  • I observe both having unique event counts for the same time window
  • I observe "lookup_editor_controller" having the "action" field while lookup_editor_rest_handler" does not

PROBLEM

  • I don't know which sourcetype I should use.

QUESTION

  • Which sourcetype should I use?
Labels (1)
Tags (3)
0 Karma
1 Solution

jsven7
Communicator

I found the data here:

index=_internal sourcetype="lookup_editor:controller" lookup_file="*"

 

View solution in original post

0 Karma

jsven7
Communicator

I found the data here:

index=_internal sourcetype="lookup_editor:controller" lookup_file="*"

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...