<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Users who are logged in right now in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/695195#M236420</link>
    <description>&lt;P&gt;This one seems better as it exclude scheduled searches.&lt;/P&gt;&lt;P&gt;index="_audit" [search index=_internal source="*web_access.log" user!="-" | stats by user | fields user] | search action="search" OR action="rtsearch" | stats values(action) as Action, values(info) as Info, max(timestamp) as lastTime, min(timestamp) as firstTime by user&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2024 04:55:40 GMT</pubDate>
    <dc:creator>Keith_wgtn</dc:creator>
    <dc:date>2024-08-05T04:55:40Z</dc:date>
    <item>
      <title>Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40204#M9249</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;Is there a search that shows all of the users that are logged in to my Splunk instance right now?&lt;/P&gt;

&lt;P&gt;I have some searches (via index=_audit) that show which users have logged on successfully but it would be good to be able to see at any time those who are currently logged in using Splunk.&lt;/P&gt;

&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2011 20:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40204#M9249</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2011-02-07T20:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40205#M9250</link>
      <description>&lt;P&gt;I use this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=_audit  NOT user="n/a" NOT user="splunk-system-user" NOT "scheduler__nobody__search" | stats max(timestamp) by user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It may not be the best, but it gives me an idea who's in the system and the last action they took.  Useful when you need to do stealth restarts in production &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2011 23:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40205#M9250</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-02-07T23:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40206#M9251</link>
      <description>&lt;P&gt;Another approach, is to look at who is currently authenticated to your &lt;CODE&gt;splunkd&lt;/CODE&gt; process.  This isn't a really a search, but it may give you the info you are looking for.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://your-splunk-server:8089/services/authentication/httpauth-tokens" rel="nofollow"&gt;https://your-splunk-server:8089/services/authentication/httpauth-tokens&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Note the "userName" field.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2011 00:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40206#M9251</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2011-02-08T00:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40207#M9252</link>
      <description>&lt;P&gt;I forgot about this question. I ended up writing a similar search that does the job&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2012 17:27:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40207#M9252</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-01-16T17:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40208#M9253</link>
      <description>&lt;P&gt;The problem with this search is that it shows users who have not logged in -- for example, audit records that track saved searches run for a particular user.&lt;/P&gt;

&lt;P&gt;I have not figured out a way to screen those out, because if the action is 'search' you can't use that to screen them because a logged-in user can also have audit records that have that action.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2013 17:10:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40208#M9253</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2013-03-06T17:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40209#M9254</link>
      <description>&lt;P&gt;You can make it into a search like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest /services/authentication/httpauth-tokens splunk_server=local | stats max(updated) by userName
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 30 Jul 2013 08:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40209#M9254</guid>
      <dc:creator>kurdbahr</dc:creator>
      <dc:date>2013-07-30T08:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40210#M9255</link>
      <description>&lt;P&gt;Very interesting. Looking at it though, it seems that 'updated' is not very helpful... it seems to always reflect the current time. I think the more interesting field is max(timeAccessed) because it appears to reflect actual last usage.&lt;/P&gt;

&lt;P&gt;I also have another search I have been using with some success:&lt;/P&gt;

&lt;P&gt;index="_audit" [search index=_internal source="*web_access.log" user!="-" | stats by user | fields user] | search action="search" OR action="rtsearch" | stats values(action) as Action, values(info) as Info, max(timestamp) as lastTime, min(timestamp) as firstTime by user&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40210#M9255</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2020-09-28T14:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40211#M9256</link>
      <description>&lt;P&gt;@wrangler2x: I think adding savedsearch_name="" to the query above would address your valid concerns about saved searches that automatically run for certain user accounts. That particular field should be non-empty if it is really a saved search.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 23:36:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40211#M9256</guid>
      <dc:creator>drapkin11</dc:creator>
      <dc:date>2013-08-06T23:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40212#M9257</link>
      <description>&lt;P&gt;index=_audit  NOT user="n/a" NOT user="splunk-system-user" NOT "scheduler&lt;EM&gt;nobody&lt;/EM&gt;_search" | stats max(timestamp) by user&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40212#M9257</guid>
      <dc:creator>neltonk</dc:creator>
      <dc:date>2020-09-29T21:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40213#M9258</link>
      <description>&lt;P&gt;Thanks wrangler2x, this is exactly what I needed!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 22:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/40213#M9258</guid>
      <dc:creator>tecooper</dc:creator>
      <dc:date>2018-10-23T22:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/544471#M154214</link>
      <description>&lt;P&gt;I made a dashboard for this.&amp;nbsp; Works fine even in a distributed setup with many search head.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;label&amp;gt;Current online users&amp;lt;/label&amp;gt;
  &amp;lt;!--
  1.0 #jotne 09.02.2021
  --&amp;gt;
  &amp;lt;search id="base_search"&amp;gt;
    &amp;lt;query&amp;gt;
      index=_audit 
      NOT user IN (n/a splunk-system-user) 
      NOT "scheduler__nobody__search"
      host="$Server$"
      user="$User$"
      | fields timestamp host user
    &amp;lt;/query&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="time"&amp;gt;
      &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-60m@m&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="dropdown" token="Server"&amp;gt;
      &amp;lt;label&amp;gt;Server&amp;lt;/label&amp;gt;
      &amp;lt;search base="base_search"&amp;gt;
        &amp;lt;query&amp;gt;
          | eval data=host
          | stats count by data
          | eval info=data." (".count.")"
          | sort -count
        &amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;choice value="*"&amp;gt;Any&amp;lt;/choice&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;info&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;data&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="dropdown" token="User"&amp;gt;
      &amp;lt;label&amp;gt;User&amp;lt;/label&amp;gt;
      &amp;lt;search base="base_search"&amp;gt;
        &amp;lt;query&amp;gt;
          | eval data=user
          | stats count by data
          | eval info=data." (".count.")"
          | sort -count
        &amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;choice value="*"&amp;gt;Any&amp;lt;/choice&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;info&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;data&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="radio" token="sort"&amp;gt;
      &amp;lt;label&amp;gt;Sort by&amp;lt;/label&amp;gt;
      &amp;lt;choice value="host"&amp;gt;Server&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="user"&amp;gt;User&amp;lt;/choice&amp;gt;
      &amp;lt;initialValue&amp;gt;host&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search base="base_search"&amp;gt;
          &amp;lt;query&amp;gt;
            | timechart count by $sort$
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;stacked&amp;lt;/option&amp;gt;
        &amp;lt;option name="height"&amp;gt;300&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="base_search"&amp;gt;
          &amp;lt;query&amp;gt;
            | stats latest(timestamp) as last_seen by user host
            | sort - last_seen&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;100&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="color" field="user"&amp;gt;
          &amp;lt;colorPalette type="sharedList"&amp;gt;&amp;lt;/colorPalette&amp;gt;
          &amp;lt;scale type="sharedCategory"&amp;gt;&amp;lt;/scale&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 09:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/544471#M154214</guid>
      <dc:creator>jotne</dc:creator>
      <dc:date>2021-03-19T09:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Users who are logged in right now</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/695195#M236420</link>
      <description>&lt;P&gt;This one seems better as it exclude scheduled searches.&lt;/P&gt;&lt;P&gt;index="_audit" [search index=_internal source="*web_access.log" user!="-" | stats by user | fields user] | search action="search" OR action="rtsearch" | stats values(action) as Action, values(info) as Info, max(timestamp) as lastTime, min(timestamp) as firstTime by user&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 04:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-who-are-logged-in-right-now/m-p/695195#M236420</guid>
      <dc:creator>Keith_wgtn</dc:creator>
      <dc:date>2024-08-05T04:55:40Z</dc:date>
    </item>
  </channel>
</rss>

