Splunk Search

Splukn audit.log file fields

rahulgopal
Explorer

Is the Splunk audit log format or the description of each field in the audit.log file documented somewhere?
I'm interested in the log entries that have to do with the search executed and the results from the search. I see the entries in the audit.log file, but would like to understand what all the fields mean.

Tags (2)
0 Karma

lukejadamec
Super Champion

I found this document helpful, section 30.5.1 Understanding the Audit Logs:

http://doc.opensuse.org/products/draft/SLES/SLES-security_sd_draft/cha.audit.comp.html#sec.audit.aur...

0 Karma

rahulgopal
Explorer

Thanks, but I'm looking for a description of these fields in the log entries for the search-request and search-results:

timestamp
user
action
info
search_id
search
buckets
ttl,
max_count
maxtime
enable_lookups
extra_fields
apiStartTime
apiEndTime
savedsearch_name
total_run_time
event_count
result_count,
available_count,
scan_count,
drop_count
exec_time
api_et
api_lt
search_e
search_lt
is_realtime

Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...