Is the Splunk audit log format or the description of each field in the audit.log file documented somewhere?
I'm interested in the log entries that have to do with the search executed and the results from the search. I see the entries in the audit.log file, but would like to understand what all the fields mean.
I found this document helpful, section 30.5.1 Understanding the Audit Logs:
http://doc.opensuse.org/products/draft/SLES/SLES-security_sd_draft/cha.audit.comp.html#sec.audit.aur...
Thanks, but I'm looking for a description of these fields in the log entries for the search-request and search-results:
timestamp
user
action
info
search_id
search
buckets
ttl,
max_count
maxtime
enable_lookups
extra_fields
apiStartTime
apiEndTime
savedsearch_name
total_run_time
event_count
result_count,
available_count,
scan_count,
drop_count
exec_time
api_et
api_lt
search_e
search_lt
is_realtime