Reporting

How to get a list of reports and searches run by a specific user?

a212830
Champion

Hi,

I need a report that shows what searches and scheduled reports that a user has run over a timeframe. I thought it was in the DMC, but I don't see it. Can someone help me?

0 Karma
1 Solution

solarboyz1
Builder
index=_audit action=search search=* NOT "typeahead" NOT metadata NOT " | history" NOT "AUTOSUMMARY" | table _time, user, search

You can reduce that to a specific user:

index=_audit action=search search=* NOT "typeahead" NOT metadata NOT " user=${user_of_interest} | history" NOT "AUTOSUMMARY" | table _time,  search

View solution in original post

sloshburch
Splunk Employee
Splunk Employee

Manage search jobs may also be of interest given the formatting and filtering already implemented for you.

0 Karma

solarboyz1
Builder

Except......that report will only contain the jobs that haven't expired. Its based on the artifacts in the dispatch directory I believe. To get historic data, you would need to use logs.

0 Karma

solarboyz1
Builder
index=_audit action=search search=* NOT "typeahead" NOT metadata NOT " | history" NOT "AUTOSUMMARY" | table _time, user, search

You can reduce that to a specific user:

index=_audit action=search search=* NOT "typeahead" NOT metadata NOT " user=${user_of_interest} | history" NOT "AUTOSUMMARY" | table _time,  search

solarboyz1
Builder

Correct a terrible paste accident in the "specific user" search syntax above:

index=_audit action=search search=* user=${user_of_interest} NOT "typeahead" NOT metadata NOT " | history" NOT "AUTOSUMMARY" | table _time, search

a212830
Champion

thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...