<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to identify user activities login / logout (reason to logout)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604564#M105136</link>
    <description>&lt;P&gt;Thanks for assistance&amp;nbsp;&lt;SPAN&gt;Giuseppe, to get on hand.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So GUI is not possible for my requirement right,&amp;nbsp; as suggested by you, I will follow the videos to get more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please help me in better understanding of this command below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=wineventlog EventCode IN ("4624","4525","4634")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 11:55:05 GMT</pubDate>
    <dc:creator>godaba</dc:creator>
    <dc:date>2022-07-06T11:55:05Z</dc:date>
    <item>
      <title>How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604497#M105124</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I am a learner, so want to know about identifying the session login / logout time periods of an users and reasons for the activities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 19:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604497#M105124</guid>
      <dc:creator>godaba</dc:creator>
      <dc:date>2022-07-05T19:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604523#M105127</link>
      <description>&lt;P&gt;Start with the data&lt;/P&gt;&lt;P&gt;Do you have it already ingested into Splunk?&lt;/P&gt;&lt;P&gt;Do you understand the data?&lt;/P&gt;&lt;P&gt;Can you write a search to find speed up interpretation of the data?&lt;/P&gt;&lt;P&gt;How do you want to represent the information you have obtained by analysing the data?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 05:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604523#M105127</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-06T05:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604538#M105130</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247439"&gt;@godaba&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Anyway, your question is just a little vague because depends on what technologies you have as inputs, what's the purpose of your analysis, and what's your knowledge of Splunk.&lt;/P&gt;&lt;P&gt;In other words:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;at first you have to list all the technologies that you have as inputs (e.f. windows, linux, Cisco ASA, etc...),&lt;/LI&gt;&lt;LI&gt;then you have to identify the rules for each source (e.g. win login is EventCode=4624, win logfail is EventCode=4625, etc...),&lt;/LI&gt;&lt;LI&gt;then you have to create an eventtype for each condition and associate to it a tag (e.g.: LOGIN, LOGOUT, LOGFAIL),&lt;/LI&gt;&lt;LI&gt;then you can run a search on these tags using SPL.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;These aren't jobs to do via GUI, for this reason I ask you: what's you knowledge of Splunk getting data in and Splunk language (SPL)?&lt;/P&gt;&lt;P&gt;You need both of them.&lt;/P&gt;&lt;P&gt;You can find many videos about getting data in on Splunk YouTube Channel and the tutorial for SPL at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 06:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604538#M105130</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-06T06:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604544#M105131</link>
      <description>&lt;P&gt;I am a learner to Splunk, as an initial requirement, just want to monitor the User's from windows ( AD Users ), when they logged in / activity performed by them / logout reason etc..Please guide if need more inputs on this. Possible to view the reports from GUI?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 07:24:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604544#M105131</guid>
      <dc:creator>godaba</dc:creator>
      <dc:date>2022-07-06T07:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604548#M105132</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247439"&gt;@godaba&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, you need at first to take and parse logs from Windows servers.&lt;/P&gt;&lt;P&gt;You can do this deploying to your Domain Controllers the Splunk_TA_Windows (&lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;Before deploying it, you have to enable the inputs, you need, for this Use Case at least wineventlog:security.&lt;/P&gt;&lt;P&gt;I suppose that you already installed and configured your Universal Forwarders to send data to Splunk Enterprise.&lt;/P&gt;&lt;P&gt;In this way, you have logs for searching.&lt;/P&gt;&lt;P&gt;So you can run a simple search like this following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog EventCode IN ("4624","4525","4634")
| stats count BY EventCode&lt;/LI-CODE&gt;&lt;P&gt;In this way you have the login, logout and logfail logs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 07:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604548#M105132</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-06T07:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604564#M105136</link>
      <description>&lt;P&gt;Thanks for assistance&amp;nbsp;&lt;SPAN&gt;Giuseppe, to get on hand.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So GUI is not possible for my requirement right,&amp;nbsp; as suggested by you, I will follow the videos to get more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please help me in better understanding of this command below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=wineventlog EventCode IN ("4624","4525","4634")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 11:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604564#M105136</guid>
      <dc:creator>godaba</dc:creator>
      <dc:date>2022-07-06T11:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify user activities login / logout (reason to logout)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604576#M105137</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247439"&gt;@godaba&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's the same thing to use:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog (EventCode=4624 OR EventCode=4525 OR EventCode=4634)&lt;/LI-CODE&gt;&lt;P&gt;Ciao.,&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 12:19:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-identify-user-activities-login-logout-reason-to-logout/m-p/604576#M105137</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-06T12:19:11Z</dc:date>
    </item>
  </channel>
</rss>

