All Apps and Add-ons

Last login time in Splunk UI not updating correctly

luispulido
Engager

Hi,

I’ve noticed an inconsistency with the Last Login Time field in Settings > Users. For two specific users, the timestamps shown in the UI don’t match what I see in the _audit index.

For one user, for example, the UI shows the last login as May 19, but _audit shows a successful login on August 18.

For another user, they have logged in at least two times after the date shown in the UI, but the Last Login Time in the UI has not updated.

It looks like the UI field is not being refreshed correctly. Has anyone else experienced this issue? Is there a known way to force the Last Login Time field to update? Does anyone know the root cause of this problem?

The Splunk version installed is 9.4.1 enterprise

Thanks in advance for your help!

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @luispulido 

I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?

It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @luispulido 

I havent noticed this myself. Are you using a Searchhead cluster? Im wondering if its showing you the last login to that specific SH rather than 'any' SH?

It might be worth raising this with support at https://www.splunk.com/support because if it is a wider bug then they can ensure it gets reported correctly and picked up by the product team.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...