Splunk Search

How to write a search to audit when an eventtype is changed?

adylent
Path Finder

Can anyone recommend a search to audit when an eventtype definition is changed?

0 Karma

lguinn2
Legend

The place to look for such things would be the _audit index, but changes to eventtypes are not tracked as far as I can tell.

0 Karma

somesoni2
Revered Legend

You want to monitor if anyone change the definition of an eventtype?

0 Karma

adylent
Path Finder

Yeah, if possible. I wasn't having any luck finding details about this in _internal

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...