Reporting

Is there way to track/audit users who made changes to reports or saved searches, and what exactly was changed in the search?

Plotkowski
Path Finder

Is there a way to track down users who made changes to reports or saved searches?
Maybe even with the information what exactly was changed in the search?

0 Karma

Runals
Motivator

I'd invite you to check out an app I made for that sort of thing - though you aren't able to see who made the change*. If you aren't able to use something like subversion an option is to use REST calls but that will only return the current configs. The main thought behind my app was to run the REST searches once a day which allows you at least to see what has changed over a period of time - new things, deleted things, changed things.

  • if it was a critical change you might be able to go back through the splunkd_ui_access logs (_internal index) and see who hit the dashboard and went to the edit screen.

https://splunkbase.splunk.com/app/2627/

0 Karma

Plotkowski
Path Finder

This looks good. Will i be able to see what exact changes where made in a search syntax of a saved search?
And is this compatible with 6.3?

0 Karma

Runals
Motivator

There is a dashboard that will show the new and old search side by side but won't highlight the specific changes. I should note though that it will only be able to show changes going forward from when you installed it. Haven't tested it with 6.3 as I'm not using that version. In theory it should work.

0 Karma

Lucas_K
Motivator

Runals,

I've just had a look at that app and it seems as if there might be some corruption/unintended files inside the app. Every single directory contains paxheader directories.

0 Karma

lycollicott
Motivator

Pax is a compression format, but not all Windows compression utilities handle it well and they create those paxheader folders when you uncompress some files. You can just delete them usually.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...