- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
search for who modified system settings in splunk cloud
jay_cambra
Observer
08-14-2024
07:08 AM
Is there a way to see who modified system settings in Splunk Cloud? For example we recently had an issue where an Splunk IP allow list was modified however we can not seem to find the activity in the _internal or _audit indexes.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
08-14-2024
12:27 PM
At least some changes could found from index _configtracker.
