for security reason, i want to log the export actions of the search result.
how to audit these actions in splunk?
Nothing in the _internal index. Maybe something in the regular system's logs apart from Splunk. Splunk should monitor and track exports of its data.
Good and necessary Enhancement Request.
DC