Splunk Search

Is there a way to Retrieve last 1000 searches performed on a particular index along with the user who performed search

splunkfriend123
Engager

Hi Team,

 

Is there any way to pull last 1000 searches performed on a particular index along with the user who performed that search

1. Splunk Query i am looking for 

 

2. Rest Query i am looking for 

 

I am running on Splunk 8.0 

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It might be possible, but it will be a challenge.  Searching index=_audit action=search will return searches executed over time along with the user who ran them.  However, the search string may not include an index name.  Some searches use default indexes and in others the index name may be embedded in a macro or otherwise obfuscated.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...