Splunk Search

Get user's search history

nawazns5038
Builder

Is there a way to get the user search activity excluding the searches given the dashboards

Thanks
N

0 Karma

niketn
Legend

@nawazns5038, I have added comments to @MuS 's answer below.

https://answers.splunk.com/answers/170477/how-do-i-get-a-list-of-all-searches-performed-in-s.html#an...

Please try out and confirm!

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

nawazns5038
Builder

Yes, looks like its working .

Thanks !

0 Karma

adonio
Ultra Champion

hello there,

start with: index=_audit action=search user=yourUser
many answers here with tips and variations for example:
https://answers.splunk.com/answers/49089/is-it-possible-to-monitor-splunk-user-activity.html
https://answers.splunk.com/answers/225682/how-to-search-splunks-internal-audit-events-to-see.html
https://answers.splunk.com/answers/77551/splunk-user-activity.html
or use your favorite search engine and try combinations like: "splunk track user activity"
also, i think that there are couple apps around this topic.

hope it helps

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...