Splunk Admin Account Activity – Account Modifications _internal john117 Vote Up +2 Vote Down -0You already voted! This Splunk query shows when the admin account performed Account Modification / Deletion / Creation actions: index=_audit user=admin action=edit_user operation=* | table _time user operation object* Share This: Tagged: _auditadmininternalsplunk on splunk