Splunk Enterprise Security

How to write a Splunk audit search?

sulaimancds
Engager

hi,

 

i need to create a query or where can i find this information.

 

i want the list of users who has run queries , for auditing purpose ,with the keyword PII on those queries which was run.

 

Please help.

 

 

Labels (2)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @sulaimancds .. the _audit index will have all splunk user's search commands (search history).

 

please check this:

https://community.splunk.com/t5/Splunk-Search/Get-user-s-search-history/m-p/57744

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...