hi,
i need to create a query or where can i find this information.
i want the list of users who has run queries , for auditing purpose ,with the keyword PII on those queries which was run.
Please help.
Hi @sulaimancds .. the _audit index will have all splunk user's search commands (search history).
please check this:
https://community.splunk.com/t5/Splunk-Search/Get-user-s-search-history/m-p/57744