Splunk Search

information about Splunk audit events

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I need to create some Correlation Searches on Splunk audit events, but I didn't find any documentation about the events to search, e.g. I don't know how to identify creation of a new role or updates to an existing one, I found only action=edit_roles, but I can only know the associted user and not the changed role.

Can anyone idicate an url to find Splunk audit information?

Ciao.

Giuseppe

Tags (1)
0 Karma

Gunnar
Explorer

Hi,

maybe the _configtracker index can help. It would have old and new values for all configuration changes including changes made to user roles.

BR!

Gunnar

gcusello
SplunkTrust
SplunkTrust

Hi @Gunnar,

thank you for your hint, in the _configtracker index there isn't any information about the user who did a change, and anyway isn't so well documented: I should search to understand events by myself, I'm searching for a documentation.

Thank you again.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...