Getting Data In

What is the best way to find computer usage statistics from Active Directory and CSV data sources?

alexlomas
Path Finder

Sorry for the question, I can't think of a sane & sensible way to get the data out of Splunk in a computationally efficient way:

Our data sources:

  • Active directory security events
  • CSVs of computer names & categories (e.g. computer*x*:public, computer*y*,private)

We want to look at the people usage of computers, but for only a subset of the computers - eg how many people used "public" computers for each hour over the last month.

Taking each computer name in turn and getting Splunk to search through the AD events looking for logons is very slow (the AD logs are 30GB+ a day). I've thought of creating a summary index with just some of the data but I can't quite figure out the best way of doing this.

Does anyone have any suggestions as to the "right" approach to take for getting these answers?

0 Karma
1 Solution

alexlomas
Path Finder

Never used data models before but they seem to fit the bill perfectly, thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...