Hi, if someone could help me out with, or point me in a nice direction to, producing a search which shows if/when a token (for API calls) is/was generated and/or deleted through either the UI or API calls, I would really appreciate it.
To be clear, the search should be using the UI though the creation/deletion of tokens could be done in either way.
Thank you in advance
It's in the audit logs. Start with this search
index=_audit ((action=edit_token_http operation=*) OR action=create)
Hm, what's the protocol here? Do I mark my own solution as "accepted solution" or the suggestion that led to the solution?
Your choice.
Today, three tokens were generated, two through API and one webUI. Two were removed using web UI.
Though looking at the available actions for past 24h I see neither "edit_token_http" or "create" listed under action.
However, your suggestion did help me achieve what I needed:
index=_audit (action=create_token OR action=remove_token)
And there we are, big thank you and have a nice weekend
Interesting. Must be a version thing. Glad you figured it out.