I am trying to figure out how to create an alert when a specific user appears in the output of the lastlog.sh script.
The output is a nicely formatted table as follows:
fri Mar 4 2:20
I am new to splunk, I cannot figure out how I would create a query that would model something like an object where I can loop through everything under the username column and then do a lookup to see if user1 exists.
Any help would be appreciated, the ultimate goal is for the query to show if "user1" appears in the output of:
any links to documentation for this would be helpful too