- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Rest API request to fetch Audit logs in Splunk Enterprise security
Chandrashekharg
Engager
01-03-2024
11:23 PM
We are looking for API request which fetch the audit logs/events performed by users in various application
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
01-05-2024
05:05 AM
Hi
unfortunately (at least I don't know) that there is separate endpoints to get splunk audit logs.
But you could get those by using search endpoint. https://docs.splunk.com/Documentation/Splunk/9.1.2/RESTREF/RESTsearch
Just create some saved searches which give you needed information and then call those or use ad hoc queries over REST api.
r. Ismo
