Splunk Search

Monitoring Searching of Sensitive Data

pagnihot
Engager

Is there a way to monitor the searches for some specific fields?

Let's say I wish to monitor if anyone is running any query that returns my SSN in the results. 

Labels (1)
0 Karma
1 Solution

burwell
SplunkTrust
SplunkTrust

Hi. You will want to look at the audit log in index _audit. You can find the search field to see what was searched for and lots more.

View solution in original post

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. You will want to look at the audit log in index _audit. You can find the search field to see what was searched for and lots more.

View solution in original post

0 Karma

pagnihot
Engager

Thank you!!

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!