stats first(_time) last(_time) count(eventid) by eventid,snarehost,access,username
note that in Splunk, first is last and last is first
if you have the date of login extracted in a field, use that field instead of _time
If I understand properly, the excel file is your outcome, and what form has the input?
To find first/last occurrence of something I would use streamstats with first()/last() function.
Hi in the excel sheet there will be 4 column which will be Event ID, First Day of Login, Last Day of Login, User ID and Number of Events,
I manage to create the Event ID, User and Number of Events by using stats count by eventid,snarehost, access, username,
BUT I'm unable to include the First Time of login and the last login during the month query.
Hope you have a clear view on this. Thanks