Dashboards & Visualizations

How to create alerts when client login session duration by UserID exceeds threshold time?

sdav124
New Member

Hello!
I am a new to developing visualizations/dashboards, can someone please guide my learning by recommending how to approach solving the following problem?

I created a search to identify the duration/time users might experience when logging into one of our applications.
The search results are placed in a table as shown below:

UserID      -----          Login Session Duration (In seconds)
bob001     ----             7s
anil002     ----            10s
chris03     ----            14s

Below is the search I am using:

  index=ags sourcetype=agslogs | tranaction startwith=Retrieving endswith=Retrieved | stats sum(duration) by UserID | rename sum(duration) as "login Duration(seconds)" | rename userID as "AGS User Name"
  • My question: With over a thousand users for this particular application, how do I take the results of the search and create email alerts for only those user login sessions that exceed the performance baseline (let's just say 10sec)? Can someone share an example search that will perform the task? Or point to an alternative approach to solving this problem?

Your assistance/guidance is highly appreciated!

0 Karma

DalJeanis
Legend

@sdav124 - I've reviewed your code, and have some questions about what you are trying to do.

You've calculated not how long any particular logon took, but the total amount of time taken by that user over whatever time you ran the query.

Perhaps you meant avg() or max() rather than sum()? I'm going to assume max() is correct, and that 10 seconds is your baseline.

index=ags sourcetype=agslogs 
| transaction startswith=Retrieving endswith=Retrieved 
| stats max(duration) as maxduration by UserID
| where maxduration> 10 
| rename userID as "AGS User Name", maxduration as "login Duration(seconds)"
0 Karma

sdav124
New Member

Typo correction...

"I am a new to developing visualizations/dashboards, can someone please guide my learning by recommending approaches to solving the following problem?"

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...