Reporting

Is there way to track/audit users who made changes to reports or saved searches, and what exactly was changed in the search?

Plotkowski
Path Finder

Is there a way to track down users who made changes to reports or saved searches?
Maybe even with the information what exactly was changed in the search?

0 Karma

Runals
Motivator

I'd invite you to check out an app I made for that sort of thing - though you aren't able to see who made the change*. If you aren't able to use something like subversion an option is to use REST calls but that will only return the current configs. The main thought behind my app was to run the REST searches once a day which allows you at least to see what has changed over a period of time - new things, deleted things, changed things.

  • if it was a critical change you might be able to go back through the splunkd_ui_access logs (_internal index) and see who hit the dashboard and went to the edit screen.

https://splunkbase.splunk.com/app/2627/

0 Karma

Plotkowski
Path Finder

This looks good. Will i be able to see what exact changes where made in a search syntax of a saved search?
And is this compatible with 6.3?

0 Karma

Runals
Motivator

There is a dashboard that will show the new and old search side by side but won't highlight the specific changes. I should note though that it will only be able to show changes going forward from when you installed it. Haven't tested it with 6.3 as I'm not using that version. In theory it should work.

0 Karma

Lucas_K
Motivator

Runals,

I've just had a look at that app and it seems as if there might be some corruption/unintended files inside the app. Every single directory contains paxheader directories.

0 Karma

lycollicott
Motivator

Pax is a compression format, but not all Windows compression utilities handle it well and they create those paxheader folders when you uncompress some files. You can just delete them usually.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...