<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279641#M84507</link>
    <description>&lt;P&gt;If it's IIS just grab the ur_stem="*"  and whatever is the parsed field for username and then table the results by those same fields ... also include _time&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2016 17:45:00 GMT</pubDate>
    <dc:creator>Jarohnimo</dc:creator>
    <dc:date>2016-07-29T17:45:00Z</dc:date>
    <item>
      <title>How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279634#M84500</link>
      <description>&lt;P&gt;I am trying to complete a request for a specific employees internet search history. I need to specify a date range, list all websites visited, and the time the searches occurred. I can't seem to get the search string right, any help would be appreciated.  &lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 21:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279634#M84500</guid>
      <dc:creator>RobertKepner</dc:creator>
      <dc:date>2016-06-02T21:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279635#M84501</link>
      <description>&lt;P&gt;It would help some of the raw data and/or your current search. &lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 22:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279635#M84501</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-06-02T22:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279636#M84502</link>
      <description>&lt;P&gt;Show a sample log and maybe we can get on with helping.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 04:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279636#M84502</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-06-03T04:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279637#M84503</link>
      <description>&lt;P&gt;Hello @RobertKepner - did you manage to get this done ?&lt;/P&gt;

&lt;P&gt;@sundareshr @woodcock&lt;BR /&gt;
I wanted to check - if fortigate logs would be enough to get this done or something else would also be needed ?&lt;BR /&gt;
I am also planning to achieve the same. i think if i shall make a search query out of fortigate data, i should be able to achieve this..&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 12:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279637#M84503</guid>
      <dc:creator>saurabh_tek</dc:creator>
      <dc:date>2016-07-22T12:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279638#M84504</link>
      <description>&lt;P&gt;I am not familiar what those logs so I cannot say.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 12:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279638#M84504</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-07-22T12:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279639#M84505</link>
      <description>&lt;P&gt;@saurabh_tek I am not familiar with the fortigate data either. If you can share a couple of events with extracted field names, we can help.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 12:53:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279639#M84505</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-07-22T12:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279640#M84506</link>
      <description>&lt;P&gt;A quick look at the fortigate log documentation says this probably is possible, but so much depends on exactly how you have the device(s) configured, if you have the &lt;A href="https://splunkbase.splunk.com/app/2800/"&gt;Splunk Fortigate App&lt;/A&gt; installed and so on.&lt;/P&gt;

&lt;P&gt;If you could please describe and provide a few examples of what logs you have available and perhaps what search you have that isn't working, we could potentially help you with this.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 01:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279640#M84506</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-07-28T01:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279641#M84507</link>
      <description>&lt;P&gt;If it's IIS just grab the ur_stem="*"  and whatever is the parsed field for username and then table the results by those same fields ... also include _time&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 17:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-a-specific-user-s-internet-activity-for-a-certain/m-p/279641#M84507</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2016-07-29T17:45:00Z</dc:date>
    </item>
  </channel>
</rss>

