Security

How to alert users who have exported dashboards?

utkarsh__
Explorer

Hi,

I have a requirement to alert all users who have pressed "export" from Splunk.

I have written the spl for listing users who have exported search results or dashboard panels.

 

 

index=_internal export | regex uri_path="(jobs|results|events)\/export$" | table user | dedup user

 

 

But this is not catching the dashboard exports. I want to alert users who have exported the complete dashboard in pdf format. Kind help will be appreciated.

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @utkarsh__,

You can use below query to find all exports including pdfs.

index=_internal pdf (sourcetype=splunkd_access OR sourcetype=splunk_pdfgen) 
| stats latest(_time) as _time values(user) as user values(filename) as filename 
| eval output_mode="pdf" 
| append 
    [ search index=_internal export sourcetype=splunkd_access 
    | regex uri_path="(jobs|results|events)\/export$" 
    | table _time user output_mode ]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

utkarsh__
Explorer

Hey @scelikok , thanks for replying.

The query only works for classic dashboards and not for the dashboard studio ones. I am not able to find any event related to studio dashboard exports. Would you please be able to help me find one.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...