All Apps and Add-ons

Last login time in Splunk UI not updating correctly

luispulido
Engager

Hi,

I’ve noticed an inconsistency with the Last Login Time field in Settings > Users. For two specific users, the timestamps shown in the UI don’t match what I see in the _audit index.

For one user, for example, the UI shows the last login as May 19, but _audit shows a successful login on August 18.

For another user, they have logged in at least two times after the date shown in the UI, but the Last Login Time in the UI has not updated.

It looks like the UI field is not being refreshed correctly. Has anyone else experienced this issue? Is there a known way to force the Last Login Time field to update? Does anyone know the root cause of this problem?

The Splunk version installed is 9.4.1 enterprise

Thanks in advance for your help!

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @luispulido 

I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?

It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @luispulido 

I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?

It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...