Hello
I've been looking at the new _configtracker index and I would like to know how I could get the User details associated with the configuration change.
Regards
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		You can't. Splunk doesn't identify the user who made the change.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		You can't. Splunk doesn't identify the user who made the change.
That's kind of what I expected. Hopefully, it will come in the next release.
Many thank for your reply, @richgalloway
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		We've been hoping for that for a long time now. 🙂 Add your voice at https://ideas.splunk.com
