Security

search for Count of users per minute for a hour

Contributor

user activities are captured in _audit index. Using this i would like to see how many users are active on a given minute for an hour. I tried this

index=_audit | dedup user | timechart span = "1m" count(user)

but dedup worked on the whole time frame instead of every minute. Any help would be appreciated.

0 Karma
1 Solution

Contributor

This is the answer for the requirement i had
index=_audit | timechart span="1m" dc(user)| rename dc(user) as "Concurrent User"

View solution in original post

Contributor

This is the answer for the requirement i had
index=_audit | timechart span="1m" dc(user)| rename dc(user) as "Concurrent User"

View solution in original post

Splunk Employee
Splunk Employee

Did this work for you?

0 Karma

Splunk Employee
Splunk Employee

What if you do the following:

... | bucket span=1m _time | dedup user, _time | timechart ...

Contributor

I want some thing like this

time user count
1m 5
2m 3
3m 20

etc

0 Karma