<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get user once per minute? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158145#M185849</link>
    <description>&lt;P&gt;Go into more detail. Why do you need to use a regular expression? What are you attempting to accomplish by it?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2015 12:54:43 GMT</pubDate>
    <dc:creator>acharlieh</dc:creator>
    <dc:date>2015-04-28T12:54:43Z</dc:date>
    <item>
      <title>How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158131#M185835</link>
      <description>&lt;P&gt;I have a query&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm\\]\\[\\]\\[\\]\\[\\]\\[\\]\\[\\]\\[(?P[^\\]]+" |bucket _time span=1m |stats count(user) as eventcount by _time, user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;From the above query i am unable to get the result&lt;/P&gt;

&lt;P&gt;Requirement what i need is .............looking for a user once per mintue in dashboard&lt;/P&gt;

&lt;P&gt;Kindly correct my Query &lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 13:43:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158131#M185835</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-27T13:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158132#M185836</link>
      <description>&lt;P&gt;Can you provide some sample events please?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 14:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158132#M185836</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-04-27T14:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158133#M185837</link>
      <description>&lt;P&gt;At the end of your query use ,&lt;BR /&gt;
|stats values(user) as user count(user) as eventcount by _time&lt;/P&gt;

&lt;P&gt;use user also after by clause i.e,&lt;BR /&gt;
|stats values(user) as USER count(user) as eventcount by _time user|fields USER eventcount&lt;/P&gt;

&lt;P&gt;But i don't think that can be fruitful.&lt;BR /&gt;
Let me know if need more assistance.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Updated Query with span of 1min...&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm\]\[\]\[\]\[\]\[\]\[\]\[(?P[^\]]+" |bucket span=5m _time|stats values(user) as USER count(user) as eventcount by _time |fields USER eventcount&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 15:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158133#M185837</guid>
      <dc:creator>neelamssantosh</dc:creator>
      <dc:date>2015-04-27T15:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158134#M185838</link>
      <description>&lt;P&gt;this is a production application&lt;BR /&gt;
and dedup on user does not give us accurate information &lt;BR /&gt;
we are not looking for the most recent login &lt;BR /&gt;
but rather ALL logins that happened&lt;BR /&gt;&lt;BR /&gt;
this is why we are only looking for a user once per minute. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 05:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158134#M185838</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T05:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158135#M185839</link>
      <description>&lt;P&gt;4/27/15 &lt;BR /&gt;
3:37:00.000 PM&lt;BR /&gt;&lt;BR /&gt;
[04/27/2015][12:37:57.821][992086960][s5036427/r60][Center realm][][][][][][206433741][][][][][][centerusushwswp222lprd][Send response attribute 147, data size is 0][]&lt;BR /&gt;
index = casm_prod&lt;BR /&gt;
4/27/15 &lt;BR /&gt;
3:37:00.000 PM&lt;BR /&gt;&lt;BR /&gt;
[04/27/2015][12:37:57.821][992086960][s5036427/r60][Center realm][][][][][][206433741][][][][][][centerusushwswp222lprd][Send response attribute 146, data size is 0][]&lt;BR /&gt;
index = casm_prod&lt;BR /&gt;
4/27/15 &lt;BR /&gt;
3:37:00.000 PM&lt;BR /&gt;&lt;BR /&gt;
[04/27/2015][12:37:57.821][992086960][s5036427/r60][Center realm][][][][][][206433741][][][][][][centerusushwswp222lprd][Send response attribute 224, data size is 16][sso_id=206433741]&lt;BR /&gt;
index = casm_prod sso_id = 206433741&lt;BR /&gt;
4/27/15 &lt;BR /&gt;
3:37:00.000 PM&lt;BR /&gt;&lt;BR /&gt;
[04/27/2015][12:37:57.821][992086960][s5036427/r60][Center realm][][][][][][206433741][][][][][][centerusushwswp222lprd][Send response attribute 224, data size is 16][smuser=206433741]&lt;BR /&gt;
index = casm_prod&lt;BR /&gt;
4/27/15 &lt;BR /&gt;
3:37:00.000 PM&lt;BR /&gt;&lt;BR /&gt;
[04/27/2015][12:37:57.821][992086960][s5036427/r60][Center realm][][][][][][206433741][][][][][][centerusushwswp222lprd][Send response attribute 224, data size is 22][georaclehrid=206433741]&lt;BR /&gt;
index = casm_prod&lt;BR /&gt;
4/27/15 &lt;BR /&gt;
3:37:00.000 PM&lt;BR /&gt;&lt;BR /&gt;
[04/27/2015][12:37:57.821][992086960][s5036427/r60][Center realm][][][][][][206433741][][][][][][centerusushwswp222lprd][Send response attribute 224, dat&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:38:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158135#M185839</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2020-09-28T19:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158136#M185840</link>
      <description>&lt;P&gt;Showing multiple login per minute&lt;/P&gt;

&lt;P&gt;can we do it only one login per minute without using dedup&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 06:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158136#M185840</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T06:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158137#M185841</link>
      <description>&lt;P&gt;Will stats by date_minute, user help instead of using stats by _time,user?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 06:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158137#M185841</guid>
      <dc:creator>vganjare</dc:creator>
      <dc:date>2015-04-28T06:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158138#M185842</link>
      <description>&lt;P&gt;Good option but will not help us as we will miss the Time field.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 06:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158138#M185842</guid>
      <dc:creator>neelamssantosh</dc:creator>
      <dc:date>2015-04-28T06:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158139#M185843</link>
      <description>&lt;P&gt;Can you give me query clearly i am unable to understand&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 06:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158139#M185843</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T06:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158140#M185844</link>
      <description>&lt;P&gt;try like :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...|bucket _time span=1m |stats count  as eventcount  by  _time,  user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...| timechart  per_minute(eval(count)) as eventcount by  _time  user
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Apr 2015 07:18:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158140#M185844</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-04-28T07:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158141#M185845</link>
      <description>&lt;P&gt;As requirement we need to use regex the time out  instead of bucket span for below query&lt;/P&gt;

&lt;P&gt;index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm][][][][][][(?P[^]]+" |bucket span=5m _time|stats values(user) as USER count(user) as eventcount by _time |fields USER eventcount. &lt;/P&gt;

&lt;P&gt;can you provide to me please,&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 07:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158141#M185845</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T07:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158142#M185846</link>
      <description>&lt;P&gt;It sounds like you want the original _time value in the results? So something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=casm_prod sourcetype=smtrace "Center realm" | eval minute=relative_time(_time,"@m") | stats first(_time) as _time, count as eventcount by minute, user
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Apr 2015 12:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158142#M185846</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-04-28T12:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158143#M185847</link>
      <description>&lt;P&gt;Reading other comments are you meaning to use &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/regex"&gt;regex&lt;/A&gt; instead of &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Rex"&gt;rex&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 12:42:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158143#M185847</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-04-28T12:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158144#M185848</link>
      <description>&lt;P&gt;In the below query we used bucket span &lt;BR /&gt;
but the requirement say need to use regex &lt;BR /&gt;
index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm][][][][][][(?P[^]]+" |bucket span=5m _time|stats values(user) as USER count(user) as eventcount by _time |fields USER eventcount&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 12:49:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158144#M185848</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T12:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158145#M185849</link>
      <description>&lt;P&gt;Go into more detail. Why do you need to use a regular expression? What are you attempting to accomplish by it?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 12:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158145#M185849</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-04-28T12:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158146#M185850</link>
      <description>&lt;P&gt;Is this an assignment of some sort?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 12:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158146#M185850</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-04-28T12:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158147#M185851</link>
      <description>&lt;P&gt;In the index for siteminder called cams_prod, &lt;BR /&gt;
there are traced filed with the type smtrace.&lt;BR /&gt;&lt;BR /&gt;
 Using these trace files find the logs for the application using 'Center realm’.&lt;BR /&gt;&lt;BR /&gt;
Then created a regular expression to mine the user. &lt;BR /&gt;
 You will notice that user are able to be found many times each minute.&lt;BR /&gt;&lt;BR /&gt;
We need to fiter this so it only shows once per minute. &lt;/P&gt;

&lt;P&gt;Can you help in building it&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 12:58:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158147#M185851</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T12:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158148#M185852</link>
      <description>&lt;P&gt;Can any one &lt;STRONG&gt;regex the time out&lt;/STRONG&gt; for below query insted of &lt;STRONG&gt;bucket span&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm][][][][][][(?P[^]]+" |bucket span=5m _time|stats values(user) as USER count(user) as eventcount by _time |fields USER eventcount&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 14:12:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158148#M185852</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T14:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158149#M185853</link>
      <description>&lt;P&gt;we need to use &lt;STRONG&gt;regex the time out&lt;/STRONG&gt;  instead of &lt;STRONG&gt;bucket span&lt;/STRONG&gt; for below query&lt;/P&gt;

&lt;P&gt;index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm][][][][][][(?P[^]]+" |bucket span=5m _time|stats values(user) as USER count(user) as eventcount by _time |fields USER eventcount. &lt;/P&gt;

&lt;P&gt;Please provide  me the query&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 14:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158149#M185853</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T14:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to get user once per minute?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158150#M185854</link>
      <description>&lt;P&gt;In the below query we used   bucket span &lt;BR /&gt;
but the requirement say need to use regex the time out&lt;/P&gt;

&lt;P&gt;index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm][][][][][][(?P[^]]+" |bucket span=5m _time|stats values(user) as USER count(user) as eventcount by _time |fields USER eventcount&lt;/P&gt;

&lt;P&gt;Please any help on it&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 14:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-user-once-per-minute/m-p/158150#M185854</guid>
      <dc:creator>moiezuddin</dc:creator>
      <dc:date>2015-04-28T14:16:50Z</dc:date>
    </item>
  </channel>
</rss>

