Reporting

Splunk Report Audit Report

dejul
New Member

Hi all, is it possible to have a report run in Splunk which reports on which reports have been run in Splunk and who ran the report.

Tags (2)
0 Karma

David
Splunk Employee
Splunk Employee

You can also audit searches in general and understand what users are doing with focused apps, such as one I built: Search Activity

0 Karma

woodcock
Esteemed Legend

In older versions of Splunk, you do it like this:

index=_internal sourcetype=searches |stats values(_raw) BY username

But starting in v5, you use the history command:

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/History

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...