Splunk Search

validate access to knowledge object

efaundez
Path Finder

Good afternoon

I am trying to perform an audit of the environmental lookups and I need to know if there is any query that allows to validate whether this knowledge object is being used or accessed

Any information is appreciated

Best regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not trivial. Start by searching all of your savedsearches.conf files for the lookup file name. Then search _internal for accesses to those searches.
Then search all of your macros.conf files for the lookup file name. Find out where those macros are used then search _internal for those searches.
Finally (if I didn't forget something), search all of your dashboards for the lookup file name then search _internal for accesses to those dashboards.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...