QuestionQ121

Clarifying the Problem

Which Splunk index is used to record user activity?

  • A _internal
  • B _kvstore
  • C _telemetry
  • D _audit
Explanation

Splunk stores audit events—including logins, logouts, searches, capability checks, and configuration changes—in the _audit index.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!