Splunk Search

How to check who has updated a lookup

nehamvinchankar
Path Finder

Hi all,

I have one lookup which was having around 1000 entries recently someone has updated the lookup and all entries got deleted. How can i know who has updated the lookup?

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could try searching the _audit index for searches which include outputlookup (assuming that this was used to update the lookup)

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...