<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic distinct count users timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40151#M9233</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are trying to track distinct current users logged in and running transactions in a particular application but cannot seem to get the correct search. Our search right now is just index=cerner | timechart span=5m dc(UserName) by host | addtotals but one of the major flaws is that within that 5min aggregation window where splunk is tallying up the users the graph shows drastic spikes which will confuse our operations center and think that there is something wrong with the application. What would be the best modification to our search syntax to ensure an accurate count of users currently logged in. If the search has to be 5 min in the past I am fine with that.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/2013-05-20_1408.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Thanks for your feedback.&lt;/P&gt;

&lt;P&gt;I made the changes and even had it offset to 5min before but it is still showing the drastic drops although the 5 min bucket window has passed. I ran the search at 8:27 an the data point at 8:20 should be accurate. Any other ideas?&lt;/P&gt;

&lt;P&gt;Thanks&lt;IMG src="http://splunk-base.splunk.com//storage/Capture_5.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2013 18:11:58 GMT</pubDate>
    <dc:creator>aaronkorn</dc:creator>
    <dc:date>2013-05-20T18:11:58Z</dc:date>
    <item>
      <title>distinct count users timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40151#M9233</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are trying to track distinct current users logged in and running transactions in a particular application but cannot seem to get the correct search. Our search right now is just index=cerner | timechart span=5m dc(UserName) by host | addtotals but one of the major flaws is that within that 5min aggregation window where splunk is tallying up the users the graph shows drastic spikes which will confuse our operations center and think that there is something wrong with the application. What would be the best modification to our search syntax to ensure an accurate count of users currently logged in. If the search has to be 5 min in the past I am fine with that.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/2013-05-20_1408.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Thanks for your feedback.&lt;/P&gt;

&lt;P&gt;I made the changes and even had it offset to 5min before but it is still showing the drastic drops although the 5 min bucket window has passed. I ran the search at 8:27 an the data point at 8:20 should be accurate. Any other ideas?&lt;/P&gt;

&lt;P&gt;Thanks&lt;IMG src="http://splunk-base.splunk.com//storage/Capture_5.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 18:11:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40151#M9233</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2013-05-20T18:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: distinct count users timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40152#M9234</link>
      <description>&lt;P&gt;Could be you need to play with the &lt;CODE&gt;partial&lt;/CODE&gt; parameter. If you run a search at say 10:06, with &lt;CODE&gt;span=5m&lt;/CODE&gt; your last timeslot will only have data for 1 minute (but be graphed like it had 5 minutes worth of data).  &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Timechart"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Timechart&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 19:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40152#M9234</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-05-20T19:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: distinct count users timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40153#M9235</link>
      <description>&lt;P&gt;thanks for your feedback. I just updated the original question trying the partial parameter.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2013 12:30:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40153#M9235</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2013-05-21T12:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: distinct count users timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40154#M9236</link>
      <description>&lt;P&gt;I couldn't figure out how to PM you from here. How are you accounting for number of users logged into Cerner? Are you getting the EMR logs from the backend, logging citrix application opens, full app launches from the desktop, or some other way I am not thinking of. I too am part of a Cerner shop and didn't realize someone else out there was tracking this as well.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2014 02:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distinct-count-users-timechart/m-p/40154#M9236</guid>
      <dc:creator>antlefebvre</dc:creator>
      <dc:date>2014-01-21T02:40:45Z</dc:date>
    </item>
  </channel>
</rss>

