Splunk Search

How to get Splunk access statistics

snevarezh
Explorer

We need to provide Splunk user access statistics:

How many user accessed splunk the last month
How many times a specific user acceded to splunk
Top 10 users who acceced to splunk
Top 10 prefered searches

and that kind of reports

Tags (1)
1 Solution

MHibbin
Influencer

There are also some nice features in the S.o.S (Splunk on Splunk) App around user activity. It was released by Splunk and as such is also supported, it's available here http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk. Once installed you can then go to "Search >> UI and User Search Activity". It also has a load of other helpful features for troubleshooting.

View solution in original post

MHibbin
Influencer

There are also some nice features in the S.o.S (Splunk on Splunk) App around user activity. It was released by Splunk and as such is also supported, it's available here http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk. Once installed you can then go to "Search >> UI and User Search Activity". It also has a load of other helpful features for troubleshooting.

sdwilkerson
Contributor

Snvarezh,

Much of what you are looking for is part of a dashboard built-in to the search app.

  1. Go to the search app
  2. On the top navigation, click on status|search activity and look the the data returned by the listed dashboards

Beyond what is there, you can click on view results to get more detail or otherwise tweak the search to more specifically find what you need.

Best,
Sean

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...