Splunk search for Access to dashboards by app

Copy
index=_internal sourcetype=splunk_web_access host=* user=* | rex field=uri_path ".*/(?<title>[^/]*)$" | join title [| rest /servicesNS/-/-/data/ui/views splunk_server=* | search isDashboard=1 isVisible=1 | rename eai:acl.app as app | fields title app ] | rename title as dashboard | stats count by _time user dashboard app host | rename user as User, dashboard as Dashboard, app as App, host as Host, count as Count
This search will show you the number of times a dashboard has been accessed, who accessed it, when it was accessed and what app it belongs to. You must be able to search Splunk's internal logs to run this search.
0 comments

Category:

General Splunk


Tags:

dashboards administration rest

Search Commands:

Sign in or Register to submit a comment