Splunk Search

Splukn audit.log file fields

rahulgopal
Explorer

Is the Splunk audit log format or the description of each field in the audit.log file documented somewhere?
I'm interested in the log entries that have to do with the search executed and the results from the search. I see the entries in the audit.log file, but would like to understand what all the fields mean.

Tags (2)
0 Karma

lukejadamec
Super Champion

I found this document helpful, section 30.5.1 Understanding the Audit Logs:

http://doc.opensuse.org/products/draft/SLES/SLES-security_sd_draft/cha.audit.comp.html#sec.audit.aur...

0 Karma

rahulgopal
Explorer

Thanks, but I'm looking for a description of these fields in the log entries for the search-request and search-results:

timestamp
user
action
info
search_id
search
buckets
ttl,
max_count
maxtime
enable_lookups
extra_fields
apiStartTime
apiEndTime
savedsearch_name
total_run_time
event_count
result_count,
available_count,
scan_count,
drop_count
exec_time
api_et
api_lt
search_e
search_lt
is_realtime

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...