Hi,
I’ve noticed an inconsistency with the Last Login Time field in Settings > Users. For two specific users, the timestamps shown in the UI don’t match what I see in the _audit index.
For one user, for example, the UI shows the last login as May 19, but _audit shows a successful login on August 18.
For another user, they have logged in at least two times after the date shown in the UI, but the Last Login Time in the UI has not updated.
It looks like the UI field is not being refreshed correctly. Has anyone else experienced this issue? Is there a known way to force the Last Login Time field to update? Does anyone know the root cause of this problem?
The Splunk version installed is 9.4.1 enterprise
Thanks in advance for your help!
Hi @luispulido
I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?
It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi @luispulido
I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?
It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing