Reporting

Splunk query to find if any changes made to the reports

Roy_9
Motivator

Hello,

Can someone help me with a search to find out whether any changes has been made to the splunk reports(ex:paloalto report) in last 30 days.

 

thanks

0 Karma

tscroggins
Influencer

Hi @Roy_9,

Changes should be logged in index=_audit:

index=_audit host IN (sh) action=modified info=succeeded savedsearch_name=xyz earliest=-30d

Replace "sh" with a list of your search head host names and "xyz" with the name of the report.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...