SPL
Splunk Admin Account Activity - Role Modifications
1 0
Description
This Splunk query shows when the admin account performed Create or Modify Roles actions:
index="_audit" action=edit_roles operation=* | table _time user operation object*
Comments
0 total
Be the first to comment on this SPL.
Leave a comment
You must log in to post a comment.