Splunk search for Access to dashboards by app
Copy
index=_internal sourcetype=splunk_web_access host=* user=*
| rex field=uri_path ".*/(?<title>[^/]*)$"
| join title
[| rest /servicesNS/-/-/data/ui/views splunk_server=*
| search isDashboard=1 isVisible=1
| rename eai:acl.app as app
| fields title app ]
| rename title as dashboard
| stats count by _time user dashboard app host | rename user as User, dashboard as Dashboard, app as App, host as Host, count as Count
This search will show you the number of times a dashboard has been accessed, who accessed it, when it was accessed and what app it belongs to. You must be able to search Splunk's internal logs to run this search.