Security

How to alert users who have exported dashboards?

utkarsh__
Explorer

Hi,

I have a requirement to alert all users who have pressed "export" from Splunk.

I have written the spl for listing users who have exported search results or dashboard panels.

 

 

index=_internal export | regex uri_path="(jobs|results|events)\/export$" | table user | dedup user

 

 

But this is not catching the dashboard exports. I want to alert users who have exported the complete dashboard in pdf format. Kind help will be appreciated.

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @utkarsh__,

You can use below query to find all exports including pdfs.

index=_internal pdf (sourcetype=splunkd_access OR sourcetype=splunk_pdfgen) 
| stats latest(_time) as _time values(user) as user values(filename) as filename 
| eval output_mode="pdf" 
| append 
    [ search index=_internal export sourcetype=splunkd_access 
    | regex uri_path="(jobs|results|events)\/export$" 
    | table _time user output_mode ]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

utkarsh__
Explorer

Hey @scelikok , thanks for replying.

The query only works for classic dashboards and not for the dashboard studio ones. I am not able to find any event related to studio dashboard exports. Would you please be able to help me find one.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...