Splunk Admin Account Activity – Role Modifications _internal john117 Vote Up +1 Vote Down -0You already voted! This Splunk query shows when the admin account performed Create or Modify Roles actions: index="_audit" action=edit_roles operation=* | table _time user operation object* Share This: Tagged: _auditadmininternalsplunk on splunk