Wednesday, October 2, 2013

Splunk Search History


For people like me -

Wondering what query you used for Search in Splunk few days back?

Try -  index=_audit action=search search=* user=userid and change time to the custom timeframe

No comments: