<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Activity Report? It is not Splunk console user activity report. in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438310#M9909</link>
    <description>&lt;P&gt;No, Out of the box Splunk can not send zipped emails.&lt;BR /&gt;
You would need to build a custom alert to do this, or simply reduce the size(bytes) of the report it generates.&lt;BR /&gt;
Either include fewer fields (using table), or fewer results (by scheduling more frequently)&lt;/P&gt;

&lt;P&gt;However a 300MB report is HUGE, what on earth does it contain!?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 14:35:09 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2019-03-12T14:35:09Z</dc:date>
    <item>
      <title>User Activity Report? It is not Splunk console user activity report.</title>
      <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438309#M9908</link>
      <description>&lt;P&gt;I created a report as like below for every 4 hours. But the problem is, Splunk does not sending the scheduled reports to email due the report size. when I download manually from "Searches, reports, and alerts", size of the csv report is approx 300MB. Is possible to schedule zip report ?&lt;/P&gt;

&lt;P&gt;Account_Name=goc_*&lt;/P&gt;

&lt;P&gt;This means i want user activity report for who started with the user account "goc_*&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438309#M9908</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2020-09-29T23:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: User Activity Report? It is not Splunk console user activity report.</title>
      <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438310#M9909</link>
      <description>&lt;P&gt;No, Out of the box Splunk can not send zipped emails.&lt;BR /&gt;
You would need to build a custom alert to do this, or simply reduce the size(bytes) of the report it generates.&lt;BR /&gt;
Either include fewer fields (using table), or fewer results (by scheduling more frequently)&lt;/P&gt;

&lt;P&gt;However a 300MB report is HUGE, what on earth does it contain!?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:35:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438310#M9909</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-12T14:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: User Activity Report? It is not Splunk console user activity report.</title>
      <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438311#M9910</link>
      <description>&lt;P&gt;I want to reduce the size of report and the report should be fewer fields (what user did on the data centre machines - Time, user name, Source IP/Host, destination IP/Host/Application, action Success/failure, what type of event is this - add, change, delete,execute ). &lt;/P&gt;

&lt;P&gt;Could you please provide the code for "User Activity Report by using Splunk ".&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 16:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438311#M9910</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2019-03-12T16:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: User Activity Report? It is not Splunk console user activity report.</title>
      <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438312#M9911</link>
      <description>&lt;P&gt;Can you provide a sample of the data the report contains, just a few rows, not the full 300 mb &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Remember to remove anything sensitive. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 16:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438312#M9911</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-12T16:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: User Activity Report? It is not Splunk console user activity report.</title>
      <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438313#M9912</link>
      <description>&lt;P&gt;Hi Nick,&lt;/P&gt;

&lt;P&gt;Here the example of scheduled report by me. &lt;/P&gt;

&lt;P&gt;Account_Name=goc_* process_name!="c:\windows\explorer.exe" &lt;/P&gt;

&lt;P&gt;_time| Host|Account_name|ComputerName|Message|Action|Account_Domain|Process_Name|Eventtype|&lt;/P&gt;

&lt;P&gt;3/12/19 1:33:48PM|DATAxx|xxxx|xxx.xx.net|An operation was attempted on a previlleged object.Subject, Security ID....| Success|xxx-NET|c:\programfiles\xx\xx.exe|Windows_previllged_object_operation|&lt;/P&gt;

&lt;P&gt;Could you please help me to get this report simple, understandable and  less size report. &lt;/P&gt;

&lt;P&gt;Thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438313#M9912</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2020-09-29T23:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: User Activity Report? It is not Splunk console user activity report.</title>
      <link>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438314#M9913</link>
      <description>&lt;P&gt;And I noticed there are many duplicate logs showing. same time stamp, same log showing in multiple times. How to avoid this?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 17:43:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/User-Activity-Report-It-is-not-Splunk-console-user-activity/m-p/438314#M9913</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2019-03-12T17:43:50Z</dc:date>
    </item>
  </channel>
</rss>

