Splunk Enterprise Security

How to differentiate between default reports/dashboards/alerts provided by splunk and one which is modified/customized/created by any user?


I need to export all reports/dashboards created/modified by 7 users (including admin's modified and excluding admin's default and "nobody" owner)

0 Karma


All default stuff shipped by splunk will be stored under default directories. Any objects created by user will be saved under $SPLUNK_HOME/etc/users/<user>/<app>/local OR $SPLUNK_HOME/etc/apps/<app>/local/(if the user shared the object at app-level).

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>