- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to get the list of Adhoc Search and Saved search running by user in Audit logs.
harishsplunk7
Explorer
09-11-2023
08:25 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-13-2023
05:24 AM
Searches are in the audit log. Saved searches will have a non-empty value in the savedsearch_name field. The user name is in the user field.
index=_audit action=search
| table user savedsearch_name search
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
harishsplunk7
Explorer
09-14-2023
05:59 AM
This is not working at all, We will get all the searches running in splunk. because there is no keyword to identify whether search is savedsearch or Ad-hoc search or Reports.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-14-2023
06:04 AM
As stated in my response, a saved search will have a non-empty value in the savedsearch_name field (keyword). If savedsearch_name="" then the search is ad-hoc.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
