Security

How to alert users who have exported dashboards?

utkarsh__
Explorer

Hi,

I have a requirement to alert all users who have pressed "export" from Splunk.

I have written the spl for listing users who have exported search results or dashboard panels.

 

 

index=_internal export | regex uri_path="(jobs|results|events)\/export$" | table user | dedup user

 

 

But this is not catching the dashboard exports. I want to alert users who have exported the complete dashboard in pdf format. Kind help will be appreciated.

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @utkarsh__,

You can use below query to find all exports including pdfs.

index=_internal pdf (sourcetype=splunkd_access OR sourcetype=splunk_pdfgen) 
| stats latest(_time) as _time values(user) as user values(filename) as filename 
| eval output_mode="pdf" 
| append 
    [ search index=_internal export sourcetype=splunkd_access 
    | regex uri_path="(jobs|results|events)\/export$" 
    | table _time user output_mode ]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

utkarsh__
Explorer

Hey @scelikok , thanks for replying.

The query only works for classic dashboards and not for the dashboard studio ones. I am not able to find any event related to studio dashboard exports. Would you please be able to help me find one.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...