Viewing the Discovery Audit Index
The Discovery Search Audit Index (discovery-audit) contains records of actions and updates made by users. Typical data written to this index includes user identity, document identity, document index, and date/time.
User actions (and pertinent data) that are recorded include:
Reporting a document (report reason)
Updating Tags (tags currently on a document, added to a document, removed from a document)
Use the Discover page in the Visualizer to look at an index’s raw data. To access the data you will need to set up an index pattern first.
Creating an Index Pattern
Open Visualizer
Select Management from the side menu
Select Index Patterns
Click Create index pattern
Search for the index you want to view (for example, discovery-audit) and enter it in the Index pattern field
Click Next step
In step 2, select "I don't want to use the Time Filter" from the Time Filter field name dropdown
Click Create index pattern
Now you can view the index data!
Viewing raw index data
In the Visualizer, select Discover from the side menu
In the top-left corner, click the down arrow to see the available indices
Select the index you want to view (for example, discovery-audit)
Drill down into records by selecting a field from the left side
You can also enter simple query structures in Search (for example, user:DOMAIN/bsmith AND documentName:Acme Purchase Order)
Select which format you wish to view the data in
Table
JSON