- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to write a Splunk audit search?
sulaimancds
Engager
03-02-2023
06:54 PM
hi,
i need to create a query or where can i find this information.
i want the list of users who has run queries , for auditing purpose ,with the keyword PII on those queries which was run.
Please help.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
inventsekar

SplunkTrust
03-02-2023
08:26 PM
Hi @sulaimancds .. the _audit index will have all splunk user's search commands (search history).
please check this:
https://community.splunk.com/t5/Splunk-Search/Get-user-s-search-history/m-p/57744
thanks and best regards,
Sekar
PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Sekar
PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
