<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Display a users time in portal by day in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/661083#M228246</link>
    <description>&lt;P&gt;This worked great, but how do I display also in the same search, what the first record was and the last record was for the durration.&lt;/P&gt;&lt;P&gt;Something like a table below&lt;/P&gt;&lt;P&gt;username, day, Duration, First, Last&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 18:26:29 GMT</pubDate>
    <dc:creator>SplunkNovice202</dc:creator>
    <dc:date>2023-10-17T18:26:29Z</dc:date>
    <item>
      <title>Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339897#M170274</link>
      <description>&lt;P&gt;Splunkers,&lt;/P&gt;

&lt;P&gt;I'm attempting to display how long a user as spent in our training portal over the last 30 days.&lt;/P&gt;

&lt;P&gt;Search string: &lt;/P&gt;

&lt;P&gt;index=blah &lt;BR /&gt;
| stats earliest(_time) as login, latest(_time) as logout by user&lt;BR /&gt;
| eval diff=logout-login&lt;BR /&gt;
| eval diff=tostring(diff, "duration")&lt;BR /&gt;
| convert timeformat="%B %d %Y %I:%M:%S %p" ctime(login)&lt;BR /&gt;
| convert timeformat="%B %d %Y %I:%M:%S %p" ctime(logout)&lt;BR /&gt;
| rename user as User, login as Login, logout as Logout, diff as "Time in Portal"&lt;/P&gt;

&lt;P&gt;Any advice would be great.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:03:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339897#M170274</guid>
      <dc:creator>matthew_foos</dc:creator>
      <dc:date>2020-09-29T19:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339898#M170275</link>
      <description>&lt;P&gt;hello there,&lt;BR /&gt;
seems like your query will calculate 1 long session for each user for 30 days.&lt;BR /&gt;
do you have an event that indicates a logon / logout?&lt;BR /&gt;
can you share some masked sample data?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 15:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339898#M170275</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-04-17T15:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339899#M170276</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I do not have an event that indicates a login / logout.  I'm calculating those fields with this:&lt;/P&gt;

&lt;P&gt;| stats earliest(_time) as login, latest(_time) as logout by user&lt;BR /&gt;
| eval diff=logout-login&lt;BR /&gt;
| eval diff=tostring(diff, "duration")&lt;/P&gt;

&lt;P&gt;This gives me a login, logout, and diff(how long they spent in the portal).&lt;/P&gt;

&lt;P&gt;Unfortunatly, this is all I have to work with..&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339899#M170276</guid>
      <dc:creator>matthew_foos</dc:creator>
      <dc:date>2020-09-29T19:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339900#M170277</link>
      <description>&lt;P&gt;hmmm,&lt;BR /&gt;
not sure how to approach this Rubiks cube. if for example user A logs in in day 1 and logs out that same day and also logs in and out on day 29, your query will capture login in day 1 and logout on day 29 and therefore calculate 28+ days on portal...&lt;BR /&gt;
can you shed some more light by sharing some masked sample data?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 15:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339900#M170277</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-04-17T15:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339901#M170278</link>
      <description>&lt;P&gt;You could try the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah 
| bucket _time as day span=1d
| stats earliest(_time) as login, latest(_time) as logout by user, day
| eval diff=logout-login
| stats sum(diff) as tip by user
| eval tip=tostring(tip, "duration")
| rename user as User, tip as "Time in Portal"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That should retrieve time in Portal per user per day, then sums it to get Time in Portal per user last 30 days&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 16:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339901#M170278</guid>
      <dc:creator>damien_chillet</dc:creator>
      <dc:date>2018-04-17T16:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339902#M170279</link>
      <description>&lt;P&gt;No results for the Time in Portal field &lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 18:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339902#M170279</guid>
      <dc:creator>matthew_foos</dc:creator>
      <dc:date>2018-04-17T18:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339903#M170280</link>
      <description>&lt;P&gt;Hey i made a mistake, i've edited the SPL, could you try one more time?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 10:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339903#M170280</guid>
      <dc:creator>damien_chillet</dc:creator>
      <dc:date>2018-04-18T10:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339904#M170281</link>
      <description>&lt;P&gt;Answered my own question:&lt;/P&gt;

&lt;P&gt;index=something&lt;BR /&gt;
| eval day=strftime(_time, "%B %d %Y") &lt;BR /&gt;
| eventstats range(_time) AS duration BY username day&lt;BR /&gt;
| stats values(duration) as duration by username day&lt;BR /&gt;
| eval duration=tostring(duration, "duration")&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/339904#M170281</guid>
      <dc:creator>matthew_foos</dc:creator>
      <dc:date>2020-09-29T19:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Display a users time in portal by day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/661083#M228246</link>
      <description>&lt;P&gt;This worked great, but how do I display also in the same search, what the first record was and the last record was for the durration.&lt;/P&gt;&lt;P&gt;Something like a table below&lt;/P&gt;&lt;P&gt;username, day, Duration, First, Last&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 18:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-a-users-time-in-portal-by-day/m-p/661083#M228246</guid>
      <dc:creator>SplunkNovice202</dc:creator>
      <dc:date>2023-10-17T18:26:29Z</dc:date>
    </item>
  </channel>
</rss>

