Index Modifications _internal john117 Vote Up +1 Vote Down -1You already voted! This Splunk query should show which users attempted to modify an index and if that action was successful: index=_audit user=* action=indexes_edit | stats count by index info user action Share This: Tagged: _auditadmininternalsplunk on splunk