All Apps and Add-ons
Highlighted

How to cluster user based on number of jobs run in Splunk Machine Learning Toolkit?

New Member

I have around 300 different users and I wanted to cluster them based on a number of jobs run. Can you please let me know how can I based the number of jobs run?

And what if I wanted to cluster them on an hourly scale when we have required fields?

0 Karma
Highlighted

Re: How to cluster user based on number of jobs run in Splunk Machine Learning Toolkit?

Motivator

Hey@jcvytla,

Can you try something like this:

index=audit action=search info=granted search=* NOT "searchid='scheduler" NOT "search='|history" NOT "user=splunk-system-user" NOT "search='typeahead" NOT "search='| metadata type=* | search totalCount>0" |table user search maxtime timestamp
And later you may add timechart as per your requirement.

Let me know if this helps!!

0 Karma
Highlighted

Re: How to cluster user based on number of jobs run in Splunk Machine Learning Toolkit?

New Member

Thanks for your solution. But, It does't seem to work. I don't get any error but data is not being populated.

Thanks

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.