Splunk Search

Finding search strings when all you have is an expired SID

davidpaper
Contributor

Greetings,

I have a saved & shared search URL that has the SID in it. The search has long expired, and I'd like to get the original search string out of it.

Looking at: index=_internal $SID sort of works, but is painful to manually parse through. There really has to be a better way to do this.

A dead-sid search perhaps?

Tags (1)
1 Solution

chris
Motivator

You can try the _audit index, this search worked for me:

index=_audit search_id='<your sid>'  info=granted | table search,savedsearch_name

View solution in original post

chris
Motivator

You can try the _audit index, this search worked for me:

index=_audit search_id='<your sid>'  info=granted | table search,savedsearch_name
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...