Monitoring Splunk

_audit index assistance

reneedeleon
Engager

Does anyone know how to setup a stats table for the _audit with all data in that index? Mainly listing all the data in the index that contain searched data or event a sample of searches you performed. Please help.

Tags (1)
0 Karma

nickhills
Ultra Champion

If you want to know who ran what searches, and how many times, you could start with something like this:

index=_audit user=* action=search search=* sourcetype=audittrail | stats count(user) by search, user

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...