Reporting

Query To Identify Who Has Exported Data

Motivator

Hi, I wonder whether someone may be able to help me please.

I've tried for a few days to find a solution online bus so far I've been unsuccessful, but could someone tell me please, is there a query which I could to see who has exported Splunk data?

Many thanks and kind regards

Chris

0 Karma
1 Solution

Contributor

May be this query will help you

index=_internal file=export | table file user uri_path

View solution in original post

Contributor

I exported a .csv using a specific name and searched for the name. I found the results using index=_internal filename=* . I'm on Splunk 6.5.2

Motivator

Hi @rewritex, thank you for taking the time to come back to me with this. The solution from @audrey2007 was slightly more what I was looking for.

Many thanks and kind regards

Chris

0 Karma

Contributor

May be this query will help you

index=_internal file=export | table file user uri_path

View solution in original post

Motivator

Hi @audrey2007, thank you for taking the time to come back to me with this. It works perfectly.

Regards

Chris

0 Karma