Security

How to find max number of concurrent users in a given day on the system? How do I find it for the last 90 days?

gopiz007
New Member

For example,
Date Max_No Time

7/2/14 75 13:00:00

7/1/14 66 18:00:00

index=login service=abc | timechart span="1h" dc(memberno) | rename dc(memberno) as users | sort - users | head 1

I want to split the events into bins of 1 hr for each day and find the distinct count of them for each hour. Once I do that I need to find the max for that day(out of the 24 bins).The above query gives me the maximum count for any given day. But I want to extend it to last 90 days. how can I do that? I want to plot a graph for the same.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Try this:

index=login service=abc earliest=-90d@d| timechart span="1h" dc(memberno) as users | timechart span=1d max(users)
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...