Splunk Search

Does Splunk capture usage metadata for each event which can be used to produce stats on most/least frequent searched event?

rado_andreev
New Member

Does Splunk capture some form of usage metadata for each event which can be used to produce stats on most/least frequent searched event?

Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee

No Splunk does not save stats on which events were searches.

the only think that you can find is the "search terms" in the audit logs.
but it will not tell you from which source/sourcetype/index/bucket the events are retrieved.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...