Splunk Search

Find search by the search id

jsanchez_splunk
Splunk Employee
Splunk Employee

I'd like to find the search query by search id. When searching the audit.log I can find the search id, but unable to locate the actual search. How can I access/view this?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Look for the search field returned by a search like this:

index=_audit action=search info=granted search_id='scheduler__nobody_U3BsdW5rX1NBX0NJTQ__RMD5eddd0618b168fff8_at_1457648640_1115'

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Look for the search field returned by a search like this:

index=_audit action=search info=granted search_id='scheduler__nobody_U3BsdW5rX1NBX0NJTQ__RMD5eddd0618b168fff8_at_1457648640_1115'

jsanchez_splunk
Splunk Employee
Splunk Employee

Gotcha...I missed the search field. Thanks!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...