Getting Data In

Help extracting user logins from IIS logs to one report

mwagnerfhlbc
Engager

Hello, I'm trying to extract two types of data from IIS logs to sum up the login counts for a list of specific users.

The IIS logs contain two entries I'm curious about specifically. If I run this search query, I get the data I'm looking for:

index=myindex host=NAMEOFSERVER "POST" "https://url.test.com/adfs/ls/" "/default.aspx" "OAuth+MSAuthHost"
AND ("DOMAIN\\User1" OR "DOMAIN\\User2") | chart count by cs_username limit=0

This will return a chart, showing the amount of times those 2 users logged via mobile for a specific time period. Now, I have another search query that gives me data I'm looking for.

index=myindex host=NAMEOFSERVER "POST" "https://url.test.com/adfs/ls/" "/default.aspx" NOT "OAuth+MSAuthHost"
AND ("DOMAIN\\User1" OR "DOMAIN\\User2") | chart count by cs_username limit=0

This will return the amount of times those 2 users logged in NOT using mobile.

What I'm trying to do is combine these two results on to one report, showing a bar chart for User1 and User2 comparing how many times they logged in via mobile (first query) and how many times they didn't (second query).

I've tried appendcol, join, just haven't had any luck combining these two datasets. Is it possible?

Thank you!

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...