I have Splunk on both of my Squid proxies forwarding the access.log to our main Splunk installation. How would I create a report of distinct domains visited by user?
You should be able to do something like this:
host=squid* source=*access.log | stats count by domain, user
Or another possible grouping would be like:
host=squid* source=*access.log | stats count, values(domain) as domains by user
You should be able to do something like this:
host=squid* source=*access.log | stats count by domain, user
Or another possible grouping would be like:
host=squid* source=*access.log | stats count, values(domain) as domains by user