<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not getting all users for splunk Usage Query in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528555#M35880</link>
    <description>&lt;P&gt;Users are missing. I am not getting the name of all the users.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 17:06:19 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2020-11-09T17:06:19Z</dc:date>
    <item>
      <title>Not getting all users for splunk Usage Query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528547#M35875</link>
      <description>&lt;P&gt;Hi All, I have used below query to check the usage of the dashboards. But I am not able to get all the users. Can someone guide me on that.&lt;/P&gt;&lt;P&gt;index=_internal sourcetype=splunkd_ui_access Infrastructure NOT splunkd user!="-" | rex field=uri "^/[^/]+/app/(?[^/]+)/(?[^?/\s]+)" | search NOT dashboard IN (alert alerts dashboards dataset datasets data_lab home lookup_edit reports report search splunk) | stats count by app dashboard user&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 15:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528547#M35875</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-11-09T15:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting all users for splunk Usage Query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528550#M35876</link>
      <description>&lt;P&gt;Not sure what the infrastructure part is doing in your search but this works for me&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd_ui_access NOT splunkd user!="-" | rex field=uri "^/[^/]+/app/(?&amp;lt;app&amp;gt;[^/]+)/(?&amp;lt;dashboard&amp;gt;[^?/\s]+)" | search NOT dashboard IN (alert alerts dashboards dataset datasets data_lab home lookup_edit reports report search splunk) | stats count by app dashboard user&lt;/LI-CODE&gt;&lt;P&gt;How do you know some users are missing? Is there something different about the events for these users?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 16:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528550#M35876</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-11-09T16:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting all users for splunk Usage Query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528551#M35877</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Infrastructure is my app name where dashboards are there . Also there are some users which visits the dashboards but whose name are not there.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 16:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528551#M35877</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-11-09T16:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting all users for splunk Usage Query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528552#M35878</link>
      <description>&lt;P&gt;Are the same users always missing? Are the events completely missing or just the user being set to "-"?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 16:42:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528552#M35878</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-11-09T16:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting all users for splunk Usage Query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528555#M35880</link>
      <description>&lt;P&gt;Users are missing. I am not getting the name of all the users.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 17:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Not-getting-all-users-for-splunk-Usage-Query/m-p/528555#M35880</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2020-11-09T17:06:19Z</dc:date>
    </item>
  </channel>
</rss>

