You should be able to find all of this information in the _audit index. All actions performed in Splunk are logged there, including admin activity.
index=_audit
For more info and examples, check the docs here: http://docs.splunk.com/Documentation/Splunk/latest/Security/AuditSplunkactivity