Hi Guys
I am looking for do a report on any log source or index setting was changed in last 7 days, where can I get these information, is that in _internal index? If I can not access _internal index is there any other way I can get these information?
In addition, I am looking for what data have been searched in last 7 days, is this information store in _internal index as well? Anywhere else or method I can get these information?
Thanks in advance
Not all config changes will be logged, even in _internal index. Could you explain what all setting you'd like to monitor?
For what people are searching in your Splunk instance, you'd need access to index=_audit.
I need to generated 2 report
1. index or log source change
2. what data has been used.
I understand these information normally stored in _internal or _audit index but since I am not admin of Splunk I cant get access to it. So I am wondering is there any other way I can get these information.
It's in _internal
- you better get access to it ; -)