Security

Monitor Role Changes in _Audit Trail

lathwal
Engager

Audit:[timestamp=10-29-2017 15:55:70.674, user=bob@bob.com, action=edit_user, info=granted object="jerry@jerry.com" operation=edit][n/a]

Is there anyway to actually see the edits that Bob made to Jerry's user account. Specifically what roles were added or removed.

Tried to use,

| rest /services/authentication/current-context splunk_server=local

but that only provides the roles that my current account has. Any help would be appreciated/

dstaulcu
Builder

Seems odd to me, too, that that the event in the audit index do not describe the nature of the role change.

0 Karma

valiquet
Contributor

You need to run with higher privilege. for REST.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...