<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which user is running search ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530333#M149845</link>
    <description>&lt;P&gt;index=_audit action=search sourcetype=audittrail search_id=* NOT (user=splunk-system-user) search!="'typeahead*"&lt;BR /&gt;| rex "search\=\'(search|\s+)\s(?P&amp;lt;search&amp;gt;[\n\S\s]+?(?=\'))"&lt;BR /&gt;| rex field=search "sourcetype\s*=\s*\"*(?&amp;lt;SourcetypeUsed&amp;gt;[^\s\"]+)"&lt;BR /&gt;| rex field=search "index\s*=\s*\"*(?&amp;lt;IndexUsed&amp;gt;[^\s\"]+)"&lt;BR /&gt;| stats latest(_time) as Latest by user search SourcetypeUsed IndexUsed&lt;BR /&gt;| convert ctime(Latest)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------&lt;/P&gt;&lt;P&gt;If this helps your like will be appreciated&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Nov 2020 12:49:00 GMT</pubDate>
    <dc:creator>vikramyadav</dc:creator>
    <dc:date>2020-11-22T12:49:00Z</dc:date>
    <item>
      <title>Which user is running search ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530320#M149841</link>
      <description>&lt;P&gt;Hi All, I have a requirement I wanted to check which user is running a search. I need help in SPL query to get user and search details.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 06:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530320#M149841</guid>
      <dc:creator>maitrifer</dc:creator>
      <dc:date>2020-11-22T06:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Which user is running search ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530323#M149843</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_audit action=search | stats earliest(user) as user ,earliest(search) as search by search_id&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 22 Nov 2020 08:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530323#M149843</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-11-22T08:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Which user is running search ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530333#M149845</link>
      <description>&lt;P&gt;index=_audit action=search sourcetype=audittrail search_id=* NOT (user=splunk-system-user) search!="'typeahead*"&lt;BR /&gt;| rex "search\=\'(search|\s+)\s(?P&amp;lt;search&amp;gt;[\n\S\s]+?(?=\'))"&lt;BR /&gt;| rex field=search "sourcetype\s*=\s*\"*(?&amp;lt;SourcetypeUsed&amp;gt;[^\s\"]+)"&lt;BR /&gt;| rex field=search "index\s*=\s*\"*(?&amp;lt;IndexUsed&amp;gt;[^\s\"]+)"&lt;BR /&gt;| stats latest(_time) as Latest by user search SourcetypeUsed IndexUsed&lt;BR /&gt;| convert ctime(Latest)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------&lt;/P&gt;&lt;P&gt;If this helps your like will be appreciated&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Nov 2020 12:49:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-user-is-running-search/m-p/530333#M149845</guid>
      <dc:creator>vikramyadav</dc:creator>
      <dc:date>2020-11-22T12:49:00Z</dc:date>
    </item>
  </channel>
</rss>

