Monitoring Splunk

Splunk Loggin of admin acess

richard_gosling
New Member

We are running a slightly older version of Splunk (4) on Centos 5.5.

I have looked around but was just wondering if the actions taken by an gui admin are logged anywhere.

ie John Smith removed server x from tag list Y?

Tags (3)
0 Karma

ftk
Motivator

You should be able to find all of this information in the _audit index. All actions performed in Splunk are logged there, including admin activity.

index=_audit

For more info and examples, check the docs here: http://docs.splunk.com/Documentation/Splunk/latest/Security/AuditSplunkactivity

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...