Splunk Enterprise Security

Splunk Enterprise security Audit logs API

Chandrashekharg
Engager

How can we fetch the events performed by users in Splunk Enterprise security product from API's?

Labels (1)
Tags (2)
0 Karma

marnall
Motivator

If you want to search the splunk internal audit events, use the _audit index
index=_audit

ref: https://docs.splunk.com/Documentation/Splunk/9.1.2/Security/AuditSplunkactivity

If you would like to fetch this information using the API, you can run a Splunk search by configuring a splunk-authenticated user with permission to read the _audit index, generating them a token, then using the REST API to dispatch a search and return the results.

Ref: https://docs.splunk.com/Documentation/Splunk/9.1.2/RESTREF/RESTsearch#search.2Fv2.2Fjobs.2Fexport

specifically the /search/v2/jobs/export endpoint, including your authorization token and the splunk search to list the audit events.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...