Splunk Search

How do I find out how many times an offensive search ran in the past day/week?

ddrillic
Ultra Champion

We have, what we believe to be an offensive search. How can we find out how many times it ran recently and by whom?

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Is it a saved search or adhoc search?? If saved search, look at index=_internal sourcetypes=scheduler savedsearch_name=YourSearchName. For adhoc searches, check index=_audit.

View solution in original post

somesoni2
Revered Legend

Is it a saved search or adhoc search?? If saved search, look at index=_internal sourcetypes=scheduler savedsearch_name=YourSearchName. For adhoc searches, check index=_audit.

ddrillic
Ultra Champion

Gorgeous !!!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...