Hi,
I have a requirement to alert all users who have pressed "export" from Splunk.
I have written the spl for listing users who have exported search results or dashboard panels.
index=_internal export | regex uri_path="(jobs|results|events)\/export$" | table user | dedup user
But this is not catching the dashboard exports. I want to alert users who have exported the complete dashboard in pdf format. Kind help will be appreciated.
Hi @utkarsh__,
You can use below query to find all exports including pdfs.
index=_internal pdf (sourcetype=splunkd_access OR sourcetype=splunk_pdfgen)
| stats latest(_time) as _time values(user) as user values(filename) as filename
| eval output_mode="pdf"
| append
[ search index=_internal export sourcetype=splunkd_access
| regex uri_path="(jobs|results|events)\/export$"
| table _time user output_mode ]
Hey @scelikok , thanks for replying.
The query only works for classic dashboards and not for the dashboard studio ones. I am not able to find any event related to studio dashboard exports. Would you please be able to help me find one.