I'd like to find the search query by search id. When searching the audit.log I can find the search id, but unable to locate the actual search. How can I access/view this?
Look for the search
field returned by a search like this:
index=_audit action=search info=granted search_id='scheduler__nobody_U3BsdW5rX1NBX0NJTQ__RMD5eddd0618b168fff8_at_1457648640_1115'
Look for the search
field returned by a search like this:
index=_audit action=search info=granted search_id='scheduler__nobody_U3BsdW5rX1NBX0NJTQ__RMD5eddd0618b168fff8_at_1457648640_1115'
Gotcha...I missed the search field. Thanks!