Which Splunk index is used to record user activity?
Splunk stores audit events—including logins, logouts, searches, capability checks, and configuration changes—in the _audit index.
_audit
Community Discussion