Reporting

Is there way to track/audit users who made changes to reports or saved searches, and what exactly was changed in the search?

Plotkowski
Path Finder

Is there a way to track down users who made changes to reports or saved searches?
Maybe even with the information what exactly was changed in the search?

0 Karma

Runals
Motivator

I'd invite you to check out an app I made for that sort of thing - though you aren't able to see who made the change*. If you aren't able to use something like subversion an option is to use REST calls but that will only return the current configs. The main thought behind my app was to run the REST searches once a day which allows you at least to see what has changed over a period of time - new things, deleted things, changed things.

  • if it was a critical change you might be able to go back through the splunkd_ui_access logs (_internal index) and see who hit the dashboard and went to the edit screen.

https://splunkbase.splunk.com/app/2627/

0 Karma

Plotkowski
Path Finder

This looks good. Will i be able to see what exact changes where made in a search syntax of a saved search?
And is this compatible with 6.3?

0 Karma

Runals
Motivator

There is a dashboard that will show the new and old search side by side but won't highlight the specific changes. I should note though that it will only be able to show changes going forward from when you installed it. Haven't tested it with 6.3 as I'm not using that version. In theory it should work.

0 Karma

Lucas_K
Motivator

Runals,

I've just had a look at that app and it seems as if there might be some corruption/unintended files inside the app. Every single directory contains paxheader directories.

0 Karma

lycollicott
Motivator

Pax is a compression format, but not all Windows compression utilities handle it well and they create those paxheader folders when you uncompress some files. You can just delete them usually.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...