Skip to main content
AuditSearch app icon

AuditSearch

Bring practical ausearch-style interpretation and filtering to raw Linux auditd events directly inside Splunk. AuditSearch performs search-time processing without modifying indexed events or requiring source-side parsing, Python, ausearch, or additional software on monitored Linux systems.Built by Hoomaan Haghparast
splunk product badge

Default Version 1.1.0

September 28, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

Rating
5
(1)

Log in to rate this app

Support
Not Supported

AuditSearch is a Splunk custom search command that brings practical ausearch-style interpretation and filtering capabilities directly into the Splunk search pipeline for raw Linux auditd events. AuditSearch is designed around a simple principle: keep the original auditd event untouched and perform interpretation at search time. Instead of modifying audit logs before they reach Splunk, installing additional parsing software on monitored Linux systems, or transforming auditd events into another format at ingestion time, AuditSearch operates on the events already indexed in Splunk. With the auditsearch command, security analysts and engineers can interpret supported auditd fields and apply audit-specific filters directly from SPL. Supported functionality includes interpretation of fields such as arch, syscall, PROCTITLE, negative exit values as errno, and supported hexadecimal audit fields. Original field values are preserved using the corresponding _raw fields, allowing analysts to work with decoded values while retaining the original representation for verification and forensic analysis. AuditSearch supports both ausearch-style syntax and Splunk-style argument forms. Common options include: -i for auditd field interpretation -k or key= for filtering by auditd key type= for filtering by audit record type auid= for filtering by login UID For example: index=linux_audit sourcetype=auditd | auditsearch -i -k rootcmd type=EXECVE auid=1000 | table _time host auid comm exe PROCTITLE AuditSearch performs its processing at search time and does not require ausearch, Python, a custom scripted input, or an AuditSearch-specific Add-on on the source Linux systems. Existing auditd forwarding configurations can remain unchanged. The command is designed for Splunk environments where raw Linux auditd data is already being collected and analysts need practical interpretation and filtering capabilities without changing the source-side audit pipeline. Because AuditSearch performs search-time processing, users should filter events as much as possible before invoking the command. Narrowing the event set with indexed fields, host, time, event type, UID, or other available filters can reduce the processing required by the command. AuditSearch is licensed under the Apache License 2.0.