Security

search for Count of users per minute for a hour

ma_anand1984
Contributor

user activities are captured in _audit index. Using this i would like to see how many users are active on a given minute for an hour. I tried this

index=_audit | dedup user | timechart span = "1m" count(user)

but dedup worked on the whole time frame instead of every minute. Any help would be appreciated.

0 Karma
1 Solution

ma_anand1984
Contributor

This is the answer for the requirement i had
index=_audit | timechart span="1m" dc(user)| rename dc(user) as "Concurrent User"

View solution in original post

ma_anand1984
Contributor

This is the answer for the requirement i had
index=_audit | timechart span="1m" dc(user)| rename dc(user) as "Concurrent User"

sdaniels
Splunk Employee
Splunk Employee

Did this work for you?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

What if you do the following:

... | bucket span=1m _time | dedup user, _time | timechart ...

ma_anand1984
Contributor

I want some thing like this

time user count
1m 5
2m 3
3m 20

etc

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...