Splunk Enterprise Security

Splunk Enterprise security Audit logs API

Chandrashekharg
Engager

How can we fetch the events performed by users in Splunk Enterprise security product from API's?

Labels (1)
Tags (2)
0 Karma

marnall
Motivator

If you want to search the splunk internal audit events, use the _audit index
index=_audit

ref: https://docs.splunk.com/Documentation/Splunk/9.1.2/Security/AuditSplunkactivity

If you would like to fetch this information using the API, you can run a Splunk search by configuring a splunk-authenticated user with permission to read the _audit index, generating them a token, then using the REST API to dispatch a search and return the results.

Ref: https://docs.splunk.com/Documentation/Splunk/9.1.2/RESTREF/RESTsearch#search.2Fv2.2Fjobs.2Fexport

specifically the /search/v2/jobs/export endpoint, including your authorization token and the splunk search to list the audit events.

 

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...