Security

What search syntax to search for VPN log history of specific user?

rhazzaguilar
New Member

What search syntax to search for VPN log history of specific user?

Tags (1)
0 Karma

lukejadamec
Super Champion
search index=yourvpnindex sourcetype=yourvpnsourcetype  "*yourspecificuser*" 

More information about what you want out of the search would be helpful.

General rules for an efficient search are to be as specific as possible with the search.

0 Karma

lukejadamec
Super Champion

Can you run a search in the Search App that shows the logs you're interested in?

If so, then do so. Look to the left. The source, sourcetype, and index will be listed. To find the index you might have to scroll to the bottom and select View All.
Post back what you find along with a pretend user name.

0 Karma

rhazzaguilar
New Member

if I am using Cisco Anyconnect, what will be my vpnindex and vpnsourcetype?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...