Splunk Search

Splukn audit.log file fields

rahulgopal
Explorer

Is the Splunk audit log format or the description of each field in the audit.log file documented somewhere?
I'm interested in the log entries that have to do with the search executed and the results from the search. I see the entries in the audit.log file, but would like to understand what all the fields mean.

Tags (2)
0 Karma

lukejadamec
Super Champion

I found this document helpful, section 30.5.1 Understanding the Audit Logs:

http://doc.opensuse.org/products/draft/SLES/SLES-security_sd_draft/cha.audit.comp.html#sec.audit.aur...

0 Karma

rahulgopal
Explorer

Thanks, but I'm looking for a description of these fields in the log entries for the search-request and search-results:

timestamp
user
action
info
search_id
search
buckets
ttl,
max_count
maxtime
enable_lookups
extra_fields
apiStartTime
apiEndTime
savedsearch_name
total_run_time
event_count
result_count,
available_count,
scan_count,
drop_count
exec_time
api_et
api_lt
search_e
search_lt
is_realtime

Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...