Is there a way to get the user search activity excluding the searches given the dashboards
Thanks
N
@nawazns5038, I have added comments to @MuS 's answer below.
Please try out and confirm!
Yes, looks like its working .
Thanks !
hello there,
start with: index=_audit action=search user=yourUser
many answers here with tips and variations for example:
https://answers.splunk.com/answers/49089/is-it-possible-to-monitor-splunk-user-activity.html
https://answers.splunk.com/answers/225682/how-to-search-splunks-internal-audit-events-to-see.html
https://answers.splunk.com/answers/77551/splunk-user-activity.html
or use your favorite search engine and try combinations like: "splunk track user activity"
also, i think that there are couple apps around this topic.
hope it helps