All Apps and Add-ons

Last login time in Splunk UI not updating correctly

luispulido
Engager

Hi,

I’ve noticed an inconsistency with the Last Login Time field in Settings > Users. For two specific users, the timestamps shown in the UI don’t match what I see in the _audit index.

For one user, for example, the UI shows the last login as May 19, but _audit shows a successful login on August 18.

For another user, they have logged in at least two times after the date shown in the UI, but the Last Login Time in the UI has not updated.

It looks like the UI field is not being refreshed correctly. Has anyone else experienced this issue? Is there a known way to force the Last Login Time field to update? Does anyone know the root cause of this problem?

The Splunk version installed is 9.4.1 enterprise

Thanks in advance for your help!

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @luispulido 

I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?

It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @luispulido 

I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?

It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...