Splunk Search

information about Splunk audit events

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I need to create some Correlation Searches on Splunk audit events, but I didn't find any documentation about the events to search, e.g. I don't know how to identify creation of a new role or updates to an existing one, I found only action=edit_roles, but I can only know the associted user and not the changed role.

Can anyone idicate an url to find Splunk audit information?

Ciao.

Giuseppe

Labels (1)
Tags (1)
0 Karma

Gunnar
Explorer

Hi,

maybe the _configtracker index can help. It would have old and new values for all configuration changes including changes made to user roles.

BR!

Gunnar

gcusello
SplunkTrust
SplunkTrust

Hi @Gunnar,

thank you for your hint, in the _configtracker index there isn't any information about the user who did a change, and anyway isn't so well documented: I should search to understand events by myself, I'm searching for a documentation.

Thank you again.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...