Monitoring Splunk

Which sourcetype to use in order to track changes made to lookup tables?

jsven7
Communicator

SITUATION

  • I'd like to track the changes done to lookup tables.
  • I observe this helpful post: "https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-the-Audit-for-Lookup-files-modificat..."
  • I observe the below sourcetypes having "Lookup edited successfully"
    • lookup_editor_rest_handler
    • lookup_editor_controller
  • I observe both having "Lookup edited successfully"
  • I observe both having unique event counts for the same time window
  • I observe "lookup_editor_controller" having the "action" field while lookup_editor_rest_handler" does not

PROBLEM

  • I don't know which sourcetype I should use.

QUESTION

  • Which sourcetype should I use?
Labels (1)
Tags (3)
0 Karma
1 Solution

jsven7
Communicator

I found the data here:

index=_internal sourcetype="lookup_editor:controller" lookup_file="*"

 

View solution in original post

0 Karma

jsven7
Communicator

I found the data here:

index=_internal sourcetype="lookup_editor:controller" lookup_file="*"

 

View solution in original post

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!