Splunk Search

information about Splunk audit events

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I need to create some Correlation Searches on Splunk audit events, but I didn't find any documentation about the events to search, e.g. I don't know how to identify creation of a new role or updates to an existing one, I found only action=edit_roles, but I can only know the associted user and not the changed role.

Can anyone idicate an url to find Splunk audit information?

Ciao.

Giuseppe

Labels (1)
Tags (1)
0 Karma

Gunnar
Explorer

Hi,

maybe the _configtracker index can help. It would have old and new values for all configuration changes including changes made to user roles.

BR!

Gunnar

gcusello
SplunkTrust
SplunkTrust

Hi @Gunnar,

thank you for your hint, in the _configtracker index there isn't any information about the user who did a change, and anyway isn't so well documented: I should search to understand events by myself, I'm searching for a documentation.

Thank you again.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...