Auditing has already been enabled but we are having issues to know who changed the permissions
Is it in here? https://docs.splunk.com/Documentation/ES/6.1.1/Admin/Logfiles#app_permissions_manager.log