Hi,
I have added couple of users in splunk using command line option. After few days few of them came back to me with login issue. I wanted to check in the log and find out whether those users were really added. Which log would have the info about user creation?
I have used the following query which shows the list of users created along with user details.
(index=_audit sourcetype=audittrail action=create_user )
| table _time action info username roles user fullname email
| rename user AS CreatedBy
It should be present in the _audit index.
Sample query:
index=_audit object=<newUserName>