Security

What search syntax to search for VPN log history of specific user?

rhazzaguilar
New Member

What search syntax to search for VPN log history of specific user?

Tags (1)
0 Karma

lukejadamec
Super Champion
search index=yourvpnindex sourcetype=yourvpnsourcetype  "*yourspecificuser*" 

More information about what you want out of the search would be helpful.

General rules for an efficient search are to be as specific as possible with the search.

0 Karma

lukejadamec
Super Champion

Can you run a search in the Search App that shows the logs you're interested in?

If so, then do so. Look to the left. The source, sourcetype, and index will be listed. To find the index you might have to scroll to the bottom and select View All.
Post back what you find along with a pretend user name.

0 Karma

rhazzaguilar
New Member

if I am using Cisco Anyconnect, what will be my vpnindex and vpnsourcetype?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...