0
votes

I am from splunk Team, we are noticing that people who are not the part of splunk team , they are doing changes in existing dashboard , without notifying us .. how can we fix this? can we do something like get notification once any changes done on any dashboard if Yes, then how? please help.

2

2 Answers

0
votes

The only way to prevent changes in Splunk is through the RBAC model - don't give "others" permissions to write to your KOs

If they have write permissions, they can write

0
votes

Check the permissions for the dashboard to make sure only the admin role (or any other role you designate) can write to it.

Splunk does not have a good way to detect/alert on dashboard changes.