Getting Data In

Total users logged in at any given time to a Windows machine

tkerr1357
Path Finder

Hello all,

I am fairly new to Splunk and am working on gathering data for our operations team. They are asking me to create a dashboard for them with relevant login/logoff security data. The part that has me stumped is getting the exact number of active users on a given machine at any time. This would normally be accomplished by launching the command line and just running query user. Any help on this one would be greatly appreciated.

Tags (2)
0 Karma

BainM
Communicator

HI tkerr1357-

You will want to use an add-on like the Splunk for Windows Add-On. This allows you to collect and index Windows events from the target server to search against. You would then search for the logon/off Window event.

App:
https://splunkbase.splunk.com/app/742/#/details
Docs:
https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows

And here's a nice front-end companion app to the backend app with dashboards and sample queries:
https://splunkbase.splunk.com/app/1680/

Hope this helps,
Mike

0 Karma

tkerr1357
Path Finder

Hi Mike, we do make use of that app however there are far more logon events then we have active users in our system at any given time. I was searching based on EventCode=4624 which is a successful logon event. Do I need to do some kind of search of successful login events and then exclude users that have logoff events within like 30 seconds or so to find total users that are logged in? if so not sure how to drill up a search like that so anything that could point in the right direction would be helpful. I will continue to review the doc's for now.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...