Security

What search syntax to search for VPN log history of specific user?

rhazzaguilar
New Member

What search syntax to search for VPN log history of specific user?

Tags (1)
0 Karma

lukejadamec
Super Champion
search index=yourvpnindex sourcetype=yourvpnsourcetype  "*yourspecificuser*" 

More information about what you want out of the search would be helpful.

General rules for an efficient search are to be as specific as possible with the search.

0 Karma

lukejadamec
Super Champion

Can you run a search in the Search App that shows the logs you're interested in?

If so, then do so. Look to the left. The source, sourcetype, and index will be listed. To find the index you might have to scroll to the bottom and select View All.
Post back what you find along with a pretend user name.

0 Karma

rhazzaguilar
New Member

if I am using Cisco Anyconnect, what will be my vpnindex and vpnsourcetype?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...