Security

How to run a search to determine whether an app has been uploaded through GUI/Rest API?

scampers
New Member

I am looking to audit any user that uploads to splunk through the User interface or REST API 

After doing some investigation I have found that the endpoints /services/app/local is the REST API endpoint that can be used to post an application. I was wondering whether splunk internally posts to that API when you utilise the GUI so by auditing that log you can get both use cases. 

I have crafted the below search to isolate these events and confirmation that this works would be awesome!

index=_internal sourcetype=splunkd_access /services/apps/local method=POST

Appreciate all assistance. 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...