Getting Data In

Help extracting user logins from IIS logs to one report

mwagnerfhlbc
Engager

Hello, I'm trying to extract two types of data from IIS logs to sum up the login counts for a list of specific users.

The IIS logs contain two entries I'm curious about specifically. If I run this search query, I get the data I'm looking for:

index=myindex host=NAMEOFSERVER "POST" "https://url.test.com/adfs/ls/" "/default.aspx" "OAuth+MSAuthHost"
AND ("DOMAIN\\User1" OR "DOMAIN\\User2") | chart count by cs_username limit=0

This will return a chart, showing the amount of times those 2 users logged via mobile for a specific time period. Now, I have another search query that gives me data I'm looking for.

index=myindex host=NAMEOFSERVER "POST" "https://url.test.com/adfs/ls/" "/default.aspx" NOT "OAuth+MSAuthHost"
AND ("DOMAIN\\User1" OR "DOMAIN\\User2") | chart count by cs_username limit=0

This will return the amount of times those 2 users logged in NOT using mobile.

What I'm trying to do is combine these two results on to one report, showing a bar chart for User1 and User2 comparing how many times they logged in via mobile (first query) and how many times they didn't (second query).

I've tried appendcol, join, just haven't had any luck combining these two datasets. Is it possible?

Thank you!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...