Getting Data In

Know what SourceTypes are being consulted by Users

mmcarty
New Member

Hello Community,

I am the administrator for a medium Splunk infrastructure
my manager came this morning and asked.

can you run a report of what users are being logged into Splunk and what searches have ran?
what of our different indexes and datasources are they being looked at?

is this possible?

Thank you!

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mmcarty,
You can find Splunk logged Users in -audit index running a search like this

index=_audit "action=login attempt"

Instead you can find infomation abour runned searches on _internal

index=_internal "search=" index

and then extract sourcetype and index fields.

Remember that in this way you find only searches where index and sourcetypes are in the search, if you have eventtypes (I usually do it!) you have to search also eventtypes.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...