<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to query time spent by user in a console in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522470#M147319</link>
    <description>Those are seconds as original values were epoch. Easiest way is to use tostring with duration:&lt;BR /&gt;&lt;BR /&gt;eval dispTime = tostring(totalsessiontime, "duration")&lt;BR /&gt;&lt;BR /&gt;r. Ismo</description>
    <pubDate>Thu, 01 Oct 2020 12:05:30 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-10-01T12:05:30Z</dc:date>
    <item>
      <title>how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/521957#M147159</link>
      <description>&lt;P&gt;Hi I want to create a report to display&amp;nbsp; time spent by user in a console&lt;/P&gt;&lt;P&gt;Being beginner doesnt know how to query .&lt;/P&gt;&lt;P&gt;Any suggestions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index="123" AND organizationId="0123000000000342" logRecordType=ailtn ("appName":"Collections_Platform" AND "appType":"Console")&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:08:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/521957#M147159</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-09-29T11:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/521960#M147162</link>
      <description>&lt;P&gt;How do you know when a user is in a console and when they are not?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/521960#M147162</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-29T11:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522017#M147181</link>
      <description>&lt;P&gt;login and logout&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522017#M147181</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-09-29T14:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522019#M147182</link>
      <description>&lt;P&gt;Cool! How do you identify which user has logged in and which has logged out? Can a user log in more than once concurrently? If concurrent, does the overlapping period get double counted? If the log in session terminates abnormally, is that also logged as an end of session? Does each event have a session id which ties all these events together?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522019#M147182</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-29T15:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522143#M147219</link>
      <description>&lt;P&gt;-We can identify the users using the userID.&lt;/P&gt;&lt;P&gt;-If a user log in more than once concurrently, overlapping period doesn't get double counted&lt;/P&gt;&lt;P&gt;-If the log in session terminates abnormally, then that will be logged as an end of session&lt;/P&gt;&lt;P&gt;-Each event do have a session id&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:54:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522143#M147219</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-09-30T04:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522149#M147221</link>
      <description>Can you give to us some scrambled example log entries so community could easier help you with this case?</description>
      <pubDate>Wed, 30 Sep 2020 05:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522149#M147221</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-30T05:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522174#M147229</link>
      <description>&lt;LI-CODE lang="markup"&gt;index="123" AND organizationId="0123000000000342" logRecordType=ailtn ("appName":"Collections_Platform" AND "appType":"Console")
| stats values(userid) as userid, earliest(_time) as startofsession, latest(_time) as endofsession by sessionid
| eval timeloggedon=endofsession-startofsession
| stats sum(timeloggedon) as totalsessiontime by userid
| fields userid totalsessiontime&lt;/LI-CODE&gt;&lt;P&gt;This assumes you have already extracted userid and sessionid&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 07:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522174#M147229</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-30T07:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522335#M147285</link>
      <description>&lt;P&gt;The events are generating but I see no data in statistics.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 18:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522335#M147285</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-09-30T18:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522465#M147318</link>
      <description>&lt;P&gt;I also want to know if the time displayed is which format and how can i format it to display in Hrs:Min&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 11:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522465#M147318</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-10-01T11:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522470#M147319</link>
      <description>Those are seconds as original values were epoch. Easiest way is to use tostring with duration:&lt;BR /&gt;&lt;BR /&gt;eval dispTime = tostring(totalsessiontime, "duration")&lt;BR /&gt;&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 01 Oct 2020 12:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522470#M147319</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-01T12:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522482#M147323</link>
      <description>&lt;P&gt;Given that your screenshot shows timeSpentOnConsole and this is a field calculate from the statistics, what data are you not seeing?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 12:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522482#M147323</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-01T12:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522536#M147333</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;The previous query you wrote wasn't returning stats so had to tweak little bit.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 16:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522536#M147333</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-10-01T16:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522538#M147335</link>
      <description>&lt;P&gt;So what do you have now and what isn't working?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 16:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522538#M147335</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-01T16:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522540#M147336</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;the dispTime column is&amp;nbsp; coming as empty using this&lt;/P&gt;&lt;P&gt;eval dispTime = tostring(totalsessiontime, "duration")&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 16:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522540#M147336</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-10-01T16:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522541#M147337</link>
      <description>&lt;P&gt;Your total session times represent multiple days. Perhaps you need to calculate days, hours, and minutes as separate values or perhaps use strftime(&lt;SPAN&gt;totalsessiontime,"%j %H:%M") although this is likely to give days as 3-digits with leading zeros, but you could strip them afterwards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 16:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522541#M147337</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-01T16:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522545#M147339</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; is this what You are asking to write as&lt;/P&gt;&lt;P&gt;stats earliest(_time) as startofsession, latest(_time) as endofsession by sessionKey userId&lt;/P&gt;&lt;P&gt;| eval timeloggedon=endofsession-startofsession&lt;/P&gt;&lt;P&gt;|eval strftime(timeloggedon,"%j %H:%M") as temp&lt;/P&gt;&lt;P&gt;|stats sum(temp) as timeSpentOnConsole by userId&lt;/P&gt;&lt;P&gt;| lookup 2clicTest.csv UserID AS userId OUTPUT Name AS NAME&lt;/P&gt;&lt;P&gt;| fields NAME timeSpentOnConsole | sort -timeSpentOnConsole | where NAME != ""&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 17:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522545#M147339</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-10-01T17:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522548#M147341</link>
      <description>&lt;LI-CODE lang="markup"&gt;stats earliest(_time) as startofsession, latest(_time) as endofsession by sessionKey userId
| eval timeloggedon=endofsession-startofsession
| stats sum(timeloggedon) as timeSpentOnConsole by userId
| lookup 2clicTest.csv UserID AS userId OUTPUT Name AS NAME
| fields NAME timeSpentOnConsole 
| sort -timeSpentOnConsole 
| where NAME != ""
| fieldformat timeSpentOnConsole = strftime(timeSpentOnConsole ,"%j %H:%M")&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 01 Oct 2020 17:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522548#M147341</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-01T17:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522552#M147342</link>
      <description>&lt;P&gt;Thanks for this.&lt;/P&gt;&lt;P&gt;One questions, multiplying days by 24 and adding it into hours would be a good approach to display time spent as hours:min&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I do that ? Or shall i simply display as strftime(timeSpentOnConsole ,"%T")&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 17:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522552#M147342</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-10-01T17:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522572#M147348</link>
      <description>&lt;P&gt;%T will take a modulus of 24. Try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;stats earliest(_time) as startofsession, latest(_time) as endofsession by sessionKey userId
| eval timeloggedon=endofsession-startofsession
| stats sum(timeloggedon) as timeSpentOnConsole by userId
| lookup 2clicTest.csv UserID AS userId OUTPUT Name AS NAME
| fields NAME timeSpentOnConsole 
| sort -timeSpentOnConsole 
| where NAME != ""
| eval hours=round(timeSpentOnConsole /(60*60))
| eval minutes=round((timeSpentOnConsole / 60) % 60)
| eval timeSpentOnConsole =tostring(hours)." hours, ".tostring(minutes)." minutes"
| fields - hours minutes&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 01 Oct 2020 18:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522572#M147348</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-01T18:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: how to query time spent by user in a console</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522635#M147378</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;you are awesome . Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 07:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-query-time-spent-by-user-in-a-console/m-p/522635#M147378</guid>
      <dc:creator>anikeshp7</dc:creator>
      <dc:date>2020-10-02T07:17:18Z</dc:date>
    </item>
  </channel>
</rss>

