Splunk Cloud Platform

How to Audit Splunk User Activities?

keperez
New Member

Dear Splunk Community,

I have tried somehow to monitor user activities with Splunk. Through the documentation I found that I can analyze it through index=_audit, however, in these records there are activities that I have not carried out directly.

For example, if I apply the query: "index=_audit user=my.user | stats count by user,action" in the last 24 hours, the result will show actions like: edit_local_apps, search, list_workload_pools, list_health, quota, edit_roles, edit_roles_grantable, etc. And of those, the only activity that I performed directly was "search".

Perhaps you know how to discriminate from all the audited actions those that I carried out directly?

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...