Splunk Search

Monitoring Searching of Sensitive Data

pagnihot
Path Finder

Is there a way to monitor the searches for some specific fields?

Let's say I wish to monitor if anyone is running any query that returns my SSN in the results. 

Labels (1)
0 Karma
1 Solution

burwell
SplunkTrust
SplunkTrust

Hi. You will want to look at the audit log in index _audit. You can find the search field to see what was searched for and lots more.

View solution in original post

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. You will want to look at the audit log in index _audit. You can find the search field to see what was searched for and lots more.

0 Karma

pagnihot
Path Finder

Thank you!!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...