<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Query for Splunk Usage in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523517#M35395</link>
    <description>&lt;P&gt;&amp;nbsp;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Below are my sourcetypes:&lt;/P&gt;&lt;P&gt;EventLogFiles&lt;/P&gt;&lt;P&gt;Extract&lt;/P&gt;&lt;P&gt;.......&lt;/P&gt;&lt;P&gt;My requirement is like I don't&amp;nbsp; want to extract something . I want to calculate the count how many times dashboard is used by user.&lt;/P&gt;&lt;P&gt;So now if I am running individual's queries for each sourcetype like this:&lt;/P&gt;&lt;P&gt;index="_internal" Extract| stats count by user&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting the result like this:&lt;/P&gt;&lt;P&gt;user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;count&lt;/P&gt;&lt;P&gt;ma20&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;30&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Similarly for the 2nd individual query:&lt;/P&gt;&lt;P&gt;index="_internal" EventLogFiles| stats count by user&amp;nbsp;&lt;/P&gt;&lt;P&gt;user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;count&lt;BR /&gt;ma20&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 15&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want to combine all into one by either using switch statement or If statement and using Eval clause.&lt;/P&gt;&lt;P&gt;Logs for your reference:(Here ma20 is the user)&lt;/P&gt;&lt;P&gt;10.2.116.4 - ma20 [07/Oct/2020:12:29:46.730 -0700] "GET /en-US/splunkd/__raw/services/search/shelper?output_mode=json&amp;amp;snippet=true&amp;amp;snippetEmbedJS=false&amp;amp;namespace=search&amp;amp;search=search+index%3D%22_internal%22+EventLogFiles%7Cstats+count+by+search+user&amp;amp;useTypeahead&lt;/P&gt;&lt;P&gt;Either something like this(Its not accurate)&lt;/P&gt;&lt;P&gt;index="_internal"&amp;nbsp;Infrastructure&lt;BR /&gt;| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles",&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;if(like(uri, "%Extract%"), "Extract",&lt;/P&gt;&lt;P&gt;"Unknown Dashboards"))&lt;BR /&gt;| stats count by DashboardName user.&lt;/P&gt;&lt;P&gt;Can you guide me on this so that I can get dashboard name,user and count by using If or swiitch.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; How can I used multiple if statements here or switch case with eval.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2020 21:32:40 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2020-10-07T21:32:40Z</dc:date>
    <item>
      <title>Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523296#M35375</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have one requirement. I have multiple dashboards . I want to calculate the usage of the dashboards based on the search user.&lt;/P&gt;&lt;P&gt;Below are my search's.&lt;/P&gt;&lt;P&gt;SplunkMetadataCounter&lt;/P&gt;&lt;P&gt;JenkinsBuildReport&lt;/P&gt;&lt;P&gt;Extract&lt;/P&gt;&lt;P&gt;......&lt;/P&gt;&lt;P&gt;......&lt;/P&gt;&lt;P&gt;For individual I am using this query:&lt;/P&gt;&lt;P&gt;index="_internal" SplunkMetadataCounter |stats count by search user.&lt;/P&gt;&lt;P&gt;I am getting the result like this:&lt;/P&gt;&lt;P&gt;search&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;user&amp;nbsp; &amp;nbsp;count&lt;/P&gt;&lt;P&gt;search+index_internal%22+SplunkMetadataCounter&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; kh&amp;nbsp; &amp;nbsp; &amp;nbsp;1&lt;/P&gt;&lt;P&gt;I want to calculate the dashboard usage on the basis of search and user: I want some query like this not sure this is accurate or not&lt;/P&gt;&lt;P&gt;index="_internal" SplunkMetadataCounter | eval dashboard_name = (if search or sourcetype contains SplunkMetadataCounter ” then dashboard name is“SplunkMetadataCounter 2” else search or sourcetype contains JenkinsBuildReport then dashboard name is“BuildReports ” .................................................) stats count by search user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the end I want one query which will tell me like SplunkMetadataCounter is used 40 times JenkinsBuildReport is used 20 times like that.&lt;/P&gt;&lt;P&gt;SplunkMetadataCounter -40&amp;nbsp;&lt;/P&gt;&lt;P&gt;JenkinsBuildReport -20&lt;/P&gt;&lt;P&gt;Extract -10&lt;/P&gt;&lt;P&gt;Can someone guide me on this.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 21:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523296#M35375</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-06T21:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523313#M35376</link>
      <description>&lt;P&gt;Can someone please guide me&amp;nbsp; for splunk usage dashboard query.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 22:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523313#M35376</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-06T22:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523324#M35377</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;&amp;nbsp;.. one warning beforehand... "Do not completely rely on current usage stats&amp;nbsp;of dashboard"..&lt;/P&gt;&lt;P&gt;Regarding the question, this query gives details about which user used which dashboard and how many times.. check it please:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" 
| rex field=referer "en-US/app/(?&amp;lt;app&amp;gt;[^/]+)/(?&amp;lt;dashboard&amp;gt;[^?/\s]+)" 
| search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home" dashboard!="alerts" dashboard!="dashboards" dashboard!="reports" dashboard!="report" 
| bucket _time span=1d 
| stats dc(dashboard) as c by dashboard user _time&lt;/LI-CODE&gt;&lt;P&gt;this spl is from&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&amp;nbsp;, thanks somesoni!&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/Ever-wonder-which-dashboards-are-being-used-and-what-users-are/td-p/262291" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/Ever-wonder-which-dashboards-are-being-used-and-what-users-are/td-p/262291&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 01:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523324#M35377</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-07T01:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523328#M35378</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This query is not working for me&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" 
| rex field=referer "en-US/app/(?&amp;lt;app&amp;gt;[^/]+)/(?&amp;lt;dashboard&amp;gt;[^?/\s]+)" 
| search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home" dashboard!="alerts" dashboard!="dashboards" dashboard!="reports" dashboard!="report" 
| bucket _time span=1d 
| stats dc(dashboard) as c by dashboard user _time&lt;/PRE&gt;&lt;P&gt;If I want to see the dashboard usage of only these two dashboards then what query I should follow:&lt;/P&gt;&lt;P&gt;SplunkMetadataCounter&amp;nbsp;&lt;/P&gt;&lt;P&gt;JenkinsBuildReport&lt;/P&gt;&lt;P&gt;I want&amp;nbsp; some query like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index="_internal" SplunkMetadataCounter | eval dashboard_name = (if search or sourcetype contains SplunkMetadataCounter ” then dashboard name is“SplunkMetadataCounter 2” else search or sourcetype contains JenkinsBuildReport then dashboard name is“BuildReports ” .................................................) stats count by search user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the end I want one query which will tell me like SplunkMetadataCounter is used 40 times JenkinsBuildReport is used 20 times like that.&lt;/P&gt;&lt;P&gt;SplunkMetadataCounter -40&amp;nbsp;&lt;/P&gt;&lt;P&gt;JenkinsBuildReport -20&lt;/P&gt;&lt;P&gt;Can someone guide me on this please.&lt;/P&gt;&lt;P&gt;Extract -10&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 05:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523328#M35378</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-07T05:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523360#M35383</link>
      <description>&lt;P&gt;The referrer field is present for events using the ReST interface, so unless you are using that on some form, you probably won't get any results.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" 
| rex "en-US/app/(?&amp;lt;app&amp;gt;[^/]+)/(?&amp;lt;dashboard&amp;gt;[^?/\s]+)" 
| search dashboard="splunkmetadatacounter" OR dashboard="jenkinsbuildreport" 
| bucket _time span=1d 
| stats dc(dashboard) as c by dashboard user _time&lt;/LI-CODE&gt;&lt;P&gt;I changed the dashboard names to lower case but even then this may not be right. You should look at your browser address bar when you are on the relevant dashboards to see how the dashboard is named in the url and use that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 07:24:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523360#M35383</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-07T07:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523371#M35384</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its not giving me the correct counts.&lt;/P&gt;&lt;P&gt;I want on the basis of search and user. When I am putting individual like this:&lt;/P&gt;&lt;P&gt;index="_internal" UserLicense| stats count by search user&lt;/P&gt;&lt;P&gt;search&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; user&lt;/P&gt;&lt;P&gt;search+index%3D%22_internal%22+GfMonitoring-UserLicense&amp;nbsp; &amp;nbsp; &amp;nbsp; 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;a&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;search+index%3D%22_internal%22+UserLicense&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;a&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;search+index%3D%22_internal%22+UserLicense%7C+stats+count+by+search&amp;nbsp; 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;search+index%3D%22_internal%22+UserLicense%7C+stats+count+by+search+user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;a&lt;/P&gt;&lt;P&gt;Below are my logs:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;10-07-2020&lt;/SPAN&gt; &lt;SPAN class="t"&gt;00:36:36.586&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-0700&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;StreamedSearch&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Streamed&lt;/SPAN&gt; &lt;SPAN class="t"&gt;search&lt;/SPAN&gt; &lt;SPAN class="t"&gt;connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;terminated:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;search_id=remote_e1_7.3.4_sh_kma__kma_RVBTRl9JbmZyYXN0cnVjdHVyZQ__search7_1602056192.7334&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;server=ssh&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;active_searches=12&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;elapsedTime=0.055&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;search=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;litsearch&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;"*" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;FolderName=&lt;/SPAN&gt;&lt;SPAN&gt;"*" (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;index=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;idx5&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;OR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;index=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;idx3&lt;/SPAN&gt;&lt;SPAN&gt;") (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;sourcetype=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Monitoring-&lt;SPAN class="t a"&gt;UserLicense&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want query like this . If search contains "&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;UserLicense" then dashboard name and its count by search user:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index="_internal" &lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;UserLicense&lt;/SPAN&gt;&lt;/SPAN&gt; | eval dashboard_name = (if search or sourcetype contains &lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;UserLicense&lt;/SPAN&gt;&lt;/SPAN&gt; ” then dashboard name is“&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;UserLicense&lt;/SPAN&gt;&lt;/SPAN&gt; ” else search or sourcetype contains JenkinsBuildReport then dashboard name is“JenkinsBuildReport ” .................................................) stats count by search user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At the end I want like this how many times dashboard is used:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;UserLicense -20&lt;/P&gt;&lt;P&gt;JenkinsBuildReport -40&lt;/P&gt;&lt;P&gt;Can you guide me on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 08:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523371#M35384</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-07T08:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523373#M35385</link>
      <description>&lt;P&gt;The log entry you provided doesn't look to me like the entry you might be interested in - for a start there doesn't appear to be a user field. Do you have some more log entries that demonstrate the events you are looking for?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 08:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523373#M35385</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-07T08:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523517#M35395</link>
      <description>&lt;P&gt;&amp;nbsp;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Below are my sourcetypes:&lt;/P&gt;&lt;P&gt;EventLogFiles&lt;/P&gt;&lt;P&gt;Extract&lt;/P&gt;&lt;P&gt;.......&lt;/P&gt;&lt;P&gt;My requirement is like I don't&amp;nbsp; want to extract something . I want to calculate the count how many times dashboard is used by user.&lt;/P&gt;&lt;P&gt;So now if I am running individual's queries for each sourcetype like this:&lt;/P&gt;&lt;P&gt;index="_internal" Extract| stats count by user&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting the result like this:&lt;/P&gt;&lt;P&gt;user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;count&lt;/P&gt;&lt;P&gt;ma20&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;30&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Similarly for the 2nd individual query:&lt;/P&gt;&lt;P&gt;index="_internal" EventLogFiles| stats count by user&amp;nbsp;&lt;/P&gt;&lt;P&gt;user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;count&lt;BR /&gt;ma20&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 15&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want to combine all into one by either using switch statement or If statement and using Eval clause.&lt;/P&gt;&lt;P&gt;Logs for your reference:(Here ma20 is the user)&lt;/P&gt;&lt;P&gt;10.2.116.4 - ma20 [07/Oct/2020:12:29:46.730 -0700] "GET /en-US/splunkd/__raw/services/search/shelper?output_mode=json&amp;amp;snippet=true&amp;amp;snippetEmbedJS=false&amp;amp;namespace=search&amp;amp;search=search+index%3D%22_internal%22+EventLogFiles%7Cstats+count+by+search+user&amp;amp;useTypeahead&lt;/P&gt;&lt;P&gt;Either something like this(Its not accurate)&lt;/P&gt;&lt;P&gt;index="_internal"&amp;nbsp;Infrastructure&lt;BR /&gt;| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles",&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;if(like(uri, "%Extract%"), "Extract",&lt;/P&gt;&lt;P&gt;"Unknown Dashboards"))&lt;BR /&gt;| stats count by DashboardName user.&lt;/P&gt;&lt;P&gt;Can you guide me on this so that I can get dashboard name,user and count by using If or swiitch.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; How can I used multiple if statements here or switch case with eval.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 21:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523517#M35395</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-07T21:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523529#M35396</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; Can you please guide me on this. How can I used multiple if statements or switch with eval for below query:&lt;/P&gt;&lt;P&gt;index="_internal"&amp;nbsp;Infrastructure&lt;BR /&gt;| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles",&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;if(like(uri, "%Extract%"), "Extract",&lt;/P&gt;&lt;P&gt;"Unknown Dashboards"))&lt;BR /&gt;| stats count by DashboardName user.&lt;/P&gt;&lt;P&gt;Your solutions always works for me please help me out.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 21:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523529#M35396</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-07T21:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523532#M35397</link>
      <description>&lt;LI-CODE lang="markup"&gt;index="_internal" Infrastructure
| eval DashboardName=case(like(uri, "%EventLogFiles%"), "EventLogFiles", like(uri, "%Extract%"), "Extract", true(), "Unknown Dashboards")
| stats count by DashboardName user&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 07 Oct 2020 21:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523532#M35397</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-07T21:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523546#M35398</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not working for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index="_internal" Infrastructure
| eval DashboardName=case(like(uri, "%EventLogFiles%"), "EventLogFiles", like(uri, "%Extract%"), "Extract", true(), "Unknown Dashboards")
| stats count by DashboardName user&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Not getting the correct counts.Its only showing the EventLogFiles and unknown dashboards(Counts are not correct) not the Extract dashboards count.&lt;/P&gt;&lt;P&gt;I tried with append not sure its correct or not.&lt;/P&gt;&lt;P&gt;index="_internal" EventLogFiles&lt;BR /&gt;| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles", "Unknown Dashboards")&lt;BR /&gt;| stats count by DashboardName user|append[search index="_internal" Extract&lt;BR /&gt;| eval DashboardName=if(like(uri, "%Extract%"), "Extract", "Unknown Dashboards")&lt;BR /&gt;| stats count by DashboardName user].&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do it without using append and get correct counts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 22:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523546#M35398</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-07T22:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523583#M35401</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I treid with below script.&lt;/P&gt;&lt;P&gt;index="_internal" Infrastructure&lt;BR /&gt;| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles",&lt;BR /&gt;if(like(uri, "%JenkinsBuildReport%"), "JenkinsBuildReport",JenkinsBuildReport",if(like(uri,"%OrgHealthCheck%"), "OrgHealthCheck",&lt;BR /&gt;"Unknown Dashboard")))|stats count by DashboardName user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DashboardName&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count&lt;BR /&gt;JenkinsBuildReport&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ma19&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 48&lt;BR /&gt;SalesforceEventLogFiles&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; math&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;BR /&gt;Unknown Dashboard&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;runel&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;643&lt;BR /&gt;Unknown Dashboard&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ma19&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2622&lt;/P&gt;&lt;P&gt;Its not showing the 3rd one&amp;nbsp;OrgHealthCheck count with user . Nor its showing the correct count event log files and Jenkins build report. Where I have gone wrong.&lt;/P&gt;&lt;P&gt;Can you guide me.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 06:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523583#M35401</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-08T06:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523594#M35403</link>
      <description>&lt;P&gt;Please repost the exact query (preferably in a code block) as there appears to have been some pasting errors.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 07:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523594#M35403</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-08T07:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for Splunk Usage</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523602#M35404</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index="_internal" Infrastructure&lt;BR /&gt;| eval DashboardName=if(like(uri, "%EventLogFiles%"), "EventLogFiles",&lt;BR /&gt;if(like(uri, "%JenkinsBuildReport%"), "JenkinsBuildReport",if(like(uri,"%OrgHealthCheck%"), "OrgHealthCheck",&lt;BR /&gt;"Unknown Dashboard")))|stats count by DashboardName user&lt;/PRE&gt;&lt;P&gt;DashboardName&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count&lt;BR /&gt;JenkinsBuildReport&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ma19&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 48&lt;BR /&gt;SalesforceEventLogFiles&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; math&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;BR /&gt;Unknown Dashboard&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;runel&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;643&lt;BR /&gt;Unknown Dashboard&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ma19&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2622&lt;/P&gt;&lt;P&gt;Its not showing the 3rd one&amp;nbsp;OrgHealthCheck count with user . Nor its showing the correct count for event log files and Jenkins build report. Where I have gone wrong.&lt;/P&gt;&lt;P&gt;Can you guide me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 07:17:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-Query-for-Splunk-Usage/m-p/523602#M35404</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-10-08T07:17:09Z</dc:date>
    </item>
  </channel>
</rss>

