Hi,
In our organization, some teams would like to see the new index logs. To explain, they want to see who created a new index. We are creating indexes via indexes conf. Is there any way to see this log by searching on the Splunk?
Thank a lot for your helps.
Splunk does not record who edited the configuration files. It sounds like you need version control for *.conf files.
Splunk does not record who edited the configuration files. It sounds like you need version control for *.conf files.