- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible to Monitor Spunk User activity of users using Splunk, based on Splunk internal Logs?
If so What would be the best place to start monitoring?, if there was an already built Splunk App for this that would be a great advantage 🙂
If the above isnt possible, what would be the best alternative?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The Splunk on Splunk app has some User Activity views.
Furthermore you can search the "_audit" index :
index=_audit | table _time user action info
The "_internal" index also has some sources on which to do username analytics ie:searches.log
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dashboard of user activity. Note: you can optionally add your own host filters for the host/search head drop-down.
<label>Activity Audit</label>
<fieldset submitButton="false">
<input type="time" token="time" searchWhenChanged="true">
<label>Time Range</label>
<input type="dropdown" token="host" searchWhenChanged="true">
<label>Host (search head)</label>
<choice value="*">All</choice>
<input type="dropdown" token="action" searchWhenChanged="true">
<choice value="*">All</choice>
<query>index=_audit sourcetype=audittrail host=$host$ action=*
| fields action
| dedup action
| table action
| sort action</query>
<input type="text" token="action_pattern" searchWhenChanged="true">
<label>Action Pattern</label>
<input type="dropdown" token="info_message" searchWhenChanged="true">
<label>Info Message</label>
<choice value="*">All</choice>
<choice value="NULL">NULL</choice>
<query>index=_audit sourcetype=audittrail host=$host$ action=*
| fields info
| dedup info
| table info
| sort info
| search NOT info="app=*"</query>
<input type="text" token="info_message_pattern" searchWhenChanged="true">
<label>Info Message Pattern</label>
<input type="dropdown" token="user" searchWhenChanged="true">
<choice value="*">All</choice>
<query>index=_audit sourcetype=audittrail host=$host$ action=*
| fields user
| dedup user
| table user
| sort user</query>
<input type="text" token="user_pattern" searchWhenChanged="true">
<label>User Pattern</label>
<input type="text" token="user_list" searchWhenChanged="true">
<label>User List (comma seperated)</label>
<title>Current Time</title>
<query>| makeresults
| eval _time=now()
| table _time</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="host">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<title>Active User Accounts</title>
<query>| rest /services/authentication/users splunk_server=local
| table defaultApp id realname email roles type splunk_server capabilities
| replace "*%40*" with "*@*" in id
| rex field=id "/users/(?<user>.+)$"
| table user realname email type roles splunk_server
| search user="$user$" user="*$user_pattern$*" user IN ($user_list$)</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="host">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="info">
<colorPalette type="map">{"succeeded":#79CA00,"failed":#D93F3C,"granted":#65A637,"completed":#A2CC3E,"canceled":#6DB7C6,"cancel":#6DB7C6,"denied":#D93F3C,"success":#B3E37D,"pause":#6DB7C6,"resume":#6DB7C6}</colorPalette>
<format type="color" field="type">
<colorPalette type="map">{"SAML":#A2CC3E,"Splunk":#F7BC38}</colorPalette>
<format type="color" field="roles">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="splunk_server">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<title>Last Action</title>
<query>index=_audit sourcetype=audittrail host=$host$
| fields _time user action info
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| sort -_time
| dedup user
| table _time user action info
| sort user</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="host">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="info">
<colorPalette type="map">{"succeeded":#79CA00,"failed":#D93F3C,"granted":#65A637,"completed":#A2CC3E,"canceled":#6DB7C6,"cancel":#6DB7C6,"denied":#D93F3C,"success":#B3E37D,"pause":#6DB7C6,"resume":#6DB7C6,"NULL":#D1D1D1}</colorPalette>
<title>Last Login Attempt</title>
<query>index=_audit sourcetype=audittrail host=$host$ action="login attempt"
| fields _time user action info
| fillnull value=NULL
| search info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| sort -_time
| dedup user
| table _time user action info
| sort user</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="host">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="info">
<colorPalette type="map">{"succeeded":#79CA00,"failed":#D93F3C,"granted":#65A637,"completed":#A2CC3E,"canceled":#6DB7C6,"cancel":#6DB7C6,"denied":#D93F3C,"success":#B3E37D,"pause":#6DB7C6,"resume":#6DB7C6}</colorPalette>
<title>Activity Timeline by Host</title>
<query>index=_audit sourcetype=audittrail host=$host$
| fields _time user action info host
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| fields _time host
| timechart count by host</query>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.chart">column</option>
<option name="charting.chart.showDataLabels">minmax</option>
<option name="charting.chart.stackMode">stacked</option>
<option name="charting.drilldown">none</option>
<option name="charting.legend.placement">bottom</option>
<option name="refresh.display">progressbar</option>
<title>Activity Timeline by User</title>
<query>index=_audit sourcetype=audittrail host=$host$
| fields _time user action info user
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| fields _time user
| timechart count by user</query>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.chart">column</option>
<option name="charting.chart.showDataLabels">minmax</option>
<option name="charting.chart.stackMode">stacked</option>
<option name="charting.drilldown">none</option>
<option name="charting.legend.placement">bottom</option>
<option name="refresh.display">progressbar</option>
<title>Activity Timeline by Action</title>
<query>index=_audit sourcetype=audittrail host=$host$
| fields _time user action info
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| fields _time action
| timechart count by action</query>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.chart">column</option>
<option name="charting.chart.showDataLabels">minmax</option>
<option name="charting.chart.stackMode">stacked</option>
<option name="charting.drilldown">none</option>
<option name="charting.legend.placement">bottom</option>
<option name="refresh.display">progressbar</option>
<title>Top Host</title>
<query>index=_audit sourcetype=audittrail host=$host$
| fields user action info host
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| fields host
| top host limit=1000</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="host">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<title>Top Users</title>
<query>index=_audit sourcetype=audittrail host=$host$ a
| fields user action info
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| fields user
| top user limit=1000</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<title>Top Actions</title>
<query>index=_audit sourcetype=audittrail host=$host$
| fields user action info
| fillnull value=NULL
| search action="*$action$" action="$action_pattern$*" info="$info_message$" info="*$info_message_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| fields action
| top action limit=1000</query>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<title>Top Actions by User and Host</title>
<query>index=_audit sourcetype=audittrail host=$host$ action=$action$ action="*$action_pattern$*" user=$user$ user="*$user_pattern$*" user IN ($user_list$)
| eval user_activity=host+"-"+user+"-"+action
| top user_activity limit=1000</query>
<option name="count">10</option>
<option name="drilldown">none</option>
<option name="refresh.display">progressbar</option>
<format type="color" field="user">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="action">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
<format type="color" field="user_activity">
<colorPalette type="sharedList"></colorPalette>
<scale type="sharedCategory"></scale>
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've used the upper example and it works just fine, but I have a small notice which I can't pass
So might not be related to this subject, but as long as it is in this page..
"This dashboard version is missing. Update the dashboard version in source."
So raised question: Where should I add/insert the dashboard tags as outside form tags is not accepted and inside form tags is not accepted too. (Edit Dashboard -> Source)
Thank you
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

<form version="1.1">
<form version="1.1" theme="dark">
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Error parsing XML on line 417: Premature end of data in tag form line 1
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @robertlynch2020 - I've corrected the paste typo.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

I used this
index=_internal sourcetype=splunkd_ui_access | stats count by clientip , user , _time | lookup dnslookup clientip | timechart span=1d distinct_count(clienthost) by clienthost limit=100
However sometimes i get users that did not log in, saying they did log in.
I think it might be due to the DNS LP address changing..
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
App S.O.S. (Splunk On Splunk) provides dashboards about that, furthermore, without any app, on right top menu, you have: Activity > System Activity > Search overview / details / user activity.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The Splunk on Splunk app has some User Activity views.
Furthermore you can search the "_audit" index :
index=_audit | table _time user action info
The "_internal" index also has some sources on which to do username analytics ie:searches.log
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, This is almost exactly what I needed.