<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Query for Dashboard/Search Query/Alert in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508356#M2530</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hello Splunkers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;Please find sample Log attached, in this UserId available. Based on this log need Splunk query to create dashboard/search query to get output.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sample Log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9591iCE37E178A3F1C8A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Sample Log.PNG" alt="Sample Log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1. The number of user logins on a Daily, Weekly or Monthly basis. (need a query for this)&lt;/P&gt;&lt;P&gt;2. The number of internal vs external user login trend.&amp;nbsp;(need a query for this)&lt;/P&gt;&lt;P&gt;3. Peak user login time of the day.&amp;nbsp;(need a query for this)&lt;/P&gt;&lt;P&gt;4. Peak user login day of the week.&amp;nbsp;(need a query for this)&lt;/P&gt;&lt;P&gt;5. Average time spent on the Platform by Users.&amp;nbsp;(need a query for this)&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2020 17:18:00 GMT</pubDate>
    <dc:creator>phanichintha</dc:creator>
    <dc:date>2020-07-09T17:18:00Z</dc:date>
    <item>
      <title>Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508356#M2530</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello Splunkers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;Please find sample Log attached, in this UserId available. Based on this log need Splunk query to create dashboard/search query to get output.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sample Log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9591iCE37E178A3F1C8A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Sample Log.PNG" alt="Sample Log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1. The number of user logins on a Daily, Weekly or Monthly basis. (need a query for this)&lt;/P&gt;&lt;P&gt;2. The number of internal vs external user login trend.&amp;nbsp;(need a query for this)&lt;/P&gt;&lt;P&gt;3. Peak user login time of the day.&amp;nbsp;(need a query for this)&lt;/P&gt;&lt;P&gt;4. Peak user login day of the week.&amp;nbsp;(need a query for this)&lt;/P&gt;&lt;P&gt;5. Average time spent on the Platform by Users.&amp;nbsp;(need a query for this)&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 17:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508356#M2530</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-09T17:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508464#M2540</link>
      <description>&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;first of all to make this easier and not need a REX if you add | table* at the end does it put all those fields you want into individual tables and of so can you provide the header names of the columns they go into?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 11:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508464#M2540</guid>
      <dc:creator>samneo</dc:creator>
      <dc:date>2020-07-10T11:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508846#M2579</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sourcetype="%forge%" source="/home/amadmin/log/authentication.audit.json" eventName=AM-LOGIN-COMPLETED OR eventName=AM-LOGOUT userId=*&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Need a query for this:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;Average time spent on the Platform by Users?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 16:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508846#M2579</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-13T16:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508988#M2601</link>
      <description>&lt;P&gt;anyone please update..&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 05:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508988#M2601</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-14T05:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508997#M2603</link>
      <description>&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Try something like the below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| stats count avg(eventName) by userId&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;| eventstats avg(eventName) as events by userId&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try one of them to see if it works for you&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 07:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/508997#M2603</guid>
      <dc:creator>samneo</dc:creator>
      <dc:date>2020-07-14T07:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509003#M2604</link>
      <description>&lt;P&gt;Hello Samneo, Thanks for your query,&lt;/P&gt;&lt;P&gt;I tried for the first case, the snap shows like this. but I need Avg time spent on login and logout by user.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanichintha_0-1594713123557.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9684i92A2698F8054E9FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanichintha_0-1594713123557.png" alt="phanichintha_0-1594713123557.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 07:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509003#M2604</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-14T07:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509010#M2605</link>
      <description>&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;When you say time spent, do you want to calculate from the time they logged in and then out and then the total to show?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 08:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509010#M2605</guid>
      <dc:creator>samneo</dc:creator>
      <dc:date>2020-07-14T08:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509011#M2606</link>
      <description>&lt;P&gt;Yes, exactly which i mean.&lt;/P&gt;&lt;P&gt;Ex: each user spent how much time on work per day.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 08:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509011#M2606</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-14T08:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509166#M2611</link>
      <description>&lt;P&gt;Hello Neo/ Anyone,&lt;/P&gt;&lt;P&gt;Can anyone please share your valuable help.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 04:28:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509166#M2611</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-15T04:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509460#M2647</link>
      <description>&lt;P&gt;Hello, can anyone help on priority, well appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 06:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509460#M2647</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-16T06:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509643#M2672</link>
      <description>&lt;P&gt;Hello, no one has answers for my questions I guess.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 05:19:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509643#M2672</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-07-17T05:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query for Dashboard/Search Query/Alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509793#M2686</link>
      <description>&lt;P data-unlink="true"&gt;Hi&amp;nbsp;phanichintha,&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;This question has been answered and is marked as solved. If you need help with a separate issue, please post a brand new question so your issue can get more visibility.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 20:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Query-for-Dashboard-Search-Query-Alert/m-p/509793#M2686</guid>
      <dc:creator>sensitive-thug</dc:creator>
      <dc:date>2020-07-17T20:37:52Z</dc:date>
    </item>
  </channel>
</rss>

