All Apps and Add-ons

How to get the history of modifications made to a lookup file?

akarivaratharaj
Communicator

I have gone through a few questions which are related to lookup file changes. I tried to use the same query to get the internal logs regarding my lookup file changes but I am unable to fetch any logs.

I would like to know where can I find the information about the changes made to my lookup file. The information is more related to the user who modified and the respective time.

I tried to search in _audit index, but I am unable to find the exact logs (may be the way of my searching is wrong)

Could anyone please help me in finding the history of modification/changes made to any lookup file?

Labels (1)
Tags (1)
0 Karma

akarivaratharaj
Communicator

Could anyone help me on this please?

0 Karma

akarivaratharaj
Communicator

I am looking this information to check the history of the modification made to a lookup file. If anyone can help me on this, it will be much appreciated!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...