<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to have SPLUNK reporting every computer usage on the network and how? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337644#M162458</link>
    <description>&lt;P&gt;I would like to be able to run a report showing the computer usage of every client on my network. Is there a way I can do it in SPLUNK?  If so what is the exact SPLUNK search command that I can use?  &lt;/P&gt;</description>
    <pubDate>Fri, 09 Mar 2018 16:03:37 GMT</pubDate>
    <dc:creator>tweedyloebus</dc:creator>
    <dc:date>2018-03-09T16:03:37Z</dc:date>
    <item>
      <title>Is it possible to have SPLUNK reporting every computer usage on the network and how?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337644#M162458</link>
      <description>&lt;P&gt;I would like to be able to run a report showing the computer usage of every client on my network. Is there a way I can do it in SPLUNK?  If so what is the exact SPLUNK search command that I can use?  &lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 16:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337644#M162458</guid>
      <dc:creator>tweedyloebus</dc:creator>
      <dc:date>2018-03-09T16:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to have SPLUNK reporting every computer usage on the network and how?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337645#M162459</link>
      <description>&lt;P&gt;If Splunk is receiving computer usage information about every client on your network then you can report on it.  The exact search depends on the computer platforms used, the data you have, and the indexes in which you store the data.&lt;BR /&gt;
If you can provide more details about your environment, we may be able to help.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 20:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337645#M162459</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-03-09T20:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to have SPLUNK reporting every computer usage on the network and how?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337646#M162460</link>
      <description>&lt;P&gt;Thank you for your reply to my post. We have Windows 7, Windows XP, Windows Server 2000, Windows Server 2008, Windows Server 2012 and Linux.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 21:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337646#M162460</guid>
      <dc:creator>tweedyloebus</dc:creator>
      <dc:date>2018-03-09T21:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to have SPLUNK reporting every computer usage on the network and how?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337647#M162461</link>
      <description>&lt;P&gt;That's not a lot to work with.  First, replace Windows XP with something recent.&lt;BR /&gt;
Second, what data are you collecting from these operating systems?  That will govern how you search.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 02:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337647#M162461</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-03-10T02:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to have SPLUNK reporting every computer usage on the network and how?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337648#M162462</link>
      <description>&lt;P&gt;Yes, Its possible. If all clients are sending data to your Splunk instance. If that's the case, can you share sample data?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 10:48:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337648#M162462</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-10T10:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to have SPLUNK reporting every computer usage on the network and how?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337649#M162463</link>
      <description>&lt;P&gt;Hi, tweedyloebus!&lt;/P&gt;

&lt;P&gt;This is a rather a big topic as you may have guessed from some of the comments so far, so let's break that down a bit.&lt;/P&gt;

&lt;P&gt;First, some background help.  The &lt;A href="https://splunkbase.splunk.com/"&gt;Splunk Fundamentals 1 class&lt;/A&gt; is free!  I'd suggest that if you haven't taken that yet to do so.  It will take about one working day to get through and will give you a decent grounding upon which to build.  &lt;/P&gt;

&lt;P&gt;Then go through the &lt;A href="https://splunkbase.splunk.com/"&gt;Splunk Tutorial&lt;/A&gt;, which is ALSO free.  This is a more "interactive" tutorial on using some actual data to do some actual things.&lt;/P&gt;

&lt;P&gt;When you have those two things completed, I think the following very vague, "list of things you'll need to do" will make a lot more sense to you.&lt;/P&gt;

&lt;P&gt;First, define what you mean by "computer usage of every client on my network."  This could mean logins and logoffs to the PCs, CPU usage of each one as the day progresses, websites they visit, or perhaps just amount of traffic they generate, and when, for all activities on the internet.  You have to define what it is you are measuring before you can measure it.&lt;/P&gt;

&lt;P&gt;Second, determine the data sources you can use for the data that would tell you this.  Using my previous examples:&lt;BR /&gt;
- Logins/Logoffs could come from Windows Event Logs and Domain Controller logs&lt;BR /&gt;
- CPU usage from perfmon&lt;BR /&gt;
- Websites (specifically) could come from any number of web proxies, or maybe your network's firewall (or possibly even the local firewalls on individual systems?)&lt;BR /&gt;
- Network traffic will come from your network's edge firewall.&lt;/P&gt;

&lt;P&gt;Third, now that you've determined what data source, you'll need to look through &lt;A href="https://splunkbase.splunk.com/"&gt;Splunkbase&lt;/A&gt; and &lt;A href="http://docs.splunk.com/Documentation"&gt;The Most Excellent Documentation&lt;/A&gt; to find out if someone else has already written an app to handle that data already.&lt;/P&gt;

&lt;P&gt;Fourth, you'll probably have to make some adjustments to that data.  In all cases, you'll have to turn on the inputs needed so that you can start collecting the data.  You haven't mentioned your Splunk environment at all - at this point I'd suggest setting up a simple &lt;EM&gt;test&lt;/EM&gt; splunk install, in addition to your production system, so you can use that for the first stab at getting this data in and make sure you are doing it right before committing it to your production instances!  (And for that, even just a smallish VM can be enough - you don't have to, for instance, turn on ALL 200 systems' event logs to it for testing - just a handful to make sure the data comes in right, is parsed correctly and will answer your questions).&lt;/P&gt;

&lt;P&gt;Fifth, well, this is where the real fun starts.  Making sense of your data!  Well, that and building cool reports and charts and helping others to really "see" what the data is telling them.&lt;/P&gt;

&lt;P&gt;Anyway, I hope this helps!  It's a big topic, but I think if you take those two pieces of free training you'll be much better off in the end!&lt;/P&gt;

&lt;P&gt;Happy Splunking,&lt;BR /&gt;
Rich&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 12:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-possible-to-have-SPLUNK-reporting-every-computer-usage-on/m-p/337649#M162463</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2018-03-11T12:54:52Z</dc:date>
    </item>
  </channel>
</rss>

