All Apps and Add-ons

One user logging into multiple systems at or around the same time - Cisco ISE

TitanAE
New Member

Writing a Splunk report that looks for multiple users logged into the same machine at or around the same time frame. I can’t think of an ISE value that would indicate a user (such as myself) logging into a machine that you’d potentially be working on. Hoping to get some advice on how to approach this.

0 Karma

pruthvikrishnap
Contributor

Hi, In Cisco ISE message catlog, there is a field for xx:xx:xx:xx/host_name which can be used to correlate this information.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...