Splunk Search

validate access to knowledge object

efaundez
Path Finder

Good afternoon

I am trying to perform an audit of the environmental lookups and I need to know if there is any query that allows to validate whether this knowledge object is being used or accessed

Any information is appreciated

Best regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not trivial. Start by searching all of your savedsearches.conf files for the lookup file name. Then search _internal for accesses to those searches.
Then search all of your macros.conf files for the lookup file name. Find out where those macros are used then search _internal for those searches.
Finally (if I didn't forget something), search all of your dashboards for the lookup file name then search _internal for accesses to those dashboards.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...