Hi,
I have a requirement to alert all users who have pressed "export" from Splunk.
I have written the spl for listing users who have exported search results or dashboard panels.
index=_internal export | regex uri_path="(jobs|results|events)\/export$" | table user | dedup user
But this is not catching the dashboard exports. I want to alert users who have exported the complete dashboard in pdf format. Kind help will be appreciated.
... View more