I have around 300 different users and I wanted to cluster them based on a number of jobs run. Can you please let me know how can I based the number of jobs run?
And what if I wanted to cluster them on an hourly scale when we have required fields?
Hey@jcvytla,
Can you try something like this:
index=_audit action=search info=granted search=* NOT "search_id='scheduler" NOT "search='|history" NOT "user=splunk-system-user" NOT "search='typeahead" NOT "search='| metadata type=* | search totalCount>0" |table user search maxtime timestamp
And later you may add timechart as per your requirement.
Let me know if this helps!!
Thanks for your solution. But, It does't seem to work. I don't get any error but data is not being populated.
Thanks