Monitoring Splunk

How to monitor Splunk changes?

guarisma
Contributor

Hello,

Looking for a way to monitor certain operational changes in Splunk like:
- A new sourcetype has been created.
- A new Input has been created.
- An input was removed/deleted.
- An Alert or Report was created or deleted.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should use version control for any conf changes made to your indexers, search heads, deployment servers, etc.. You can also leverage the internal log to answer the alert/report modification

index=_audit

0 Karma

guarisma
Contributor

What event will tell me a new index was created in Splunk Cloud?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Yeah, this is available in the audit index too. Please accept the answer if this answered your questions

index=_audit action=indexes_edit

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...