Security

How can I audit changes made to Splunk Role Index access?

nthornbury
Explorer

Can someone point me in the right direction to find info concerning auditing Splunk Cloud role changes? Specifically, I need to find out who/when an index access change occurred for a role in our Splunk Cloud deployment. I have tried searching the audit index, yet I don't get any info that says: `this user account________ on this date__________ modified the index access list for this role________`?

Thank you.

0 Karma
1 Solution

nthornbury
Explorer
0 Karma

nthornbury
Explorer

Peter,

I developed a report that runs each week, and sends me the reults fo the following search string:

index=_audit source=audittrail operation=edit action!=search action=edit_roles

You could modify this search with other parameters that suit your particular needs or frequency. The above, will show you all mods made to the admin role. I hope that helps. Thanks!

nthornbury
Explorer

Problem Solved.

0 Karma

randy_moore
Path Finder

@nthornbury - Were you ever able to get this solved?

0 Karma

nthornbury
Explorer

Yes, I am good to go on this one. Thank you for the follow-up!

0 Karma

peter_krammer
Communicator

Would you be so kind and share how you solved it, so that others can benefit from the info.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...