Hello
I've been looking at the new _configtracker index and I would like to know how I could get the User details associated with the configuration change.
Regards
You can't. Splunk doesn't identify the user who made the change.
You can't. Splunk doesn't identify the user who made the change.
That's kind of what I expected. Hopefully, it will come in the next release.
Many thank for your reply, @richgalloway
We've been hoping for that for a long time now. 🙂 Add your voice at https://ideas.splunk.com