You can also audit searches in general and understand what users are doing with focused apps, such as one I built: Search Activity
In older versions of Splunk, you do it like this:
index=_internal sourcetype=searches |stats values(_raw) BY username
But starting in v5, you use the history
command:
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/History