Splunk Search

Splukn audit.log file fields

rahulgopal
Explorer

Is the Splunk audit log format or the description of each field in the audit.log file documented somewhere?
I'm interested in the log entries that have to do with the search executed and the results from the search. I see the entries in the audit.log file, but would like to understand what all the fields mean.

Tags (2)
0 Karma

lukejadamec
Super Champion

I found this document helpful, section 30.5.1 Understanding the Audit Logs:

http://doc.opensuse.org/products/draft/SLES/SLES-security_sd_draft/cha.audit.comp.html#sec.audit.aur...

0 Karma

rahulgopal
Explorer

Thanks, but I'm looking for a description of these fields in the log entries for the search-request and search-results:

timestamp
user
action
info
search_id
search
buckets
ttl,
max_count
maxtime
enable_lookups
extra_fields
apiStartTime
apiEndTime
savedsearch_name
total_run_time
event_count
result_count,
available_count,
scan_count,
drop_count
exec_time
api_et
api_lt
search_e
search_lt
is_realtime

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...