Splunk Enterprise Security

How to create a table to display different users who logged in from same clientip?

Win
Explorer

Hi, I am a student and new to Splunk. I really need help creating a table like this:

The goal is to detect different users that authenticated using same clientIP, different httpmethod, different status codes, and its equivalent sessionid. I used the below query, which yielded no results.

 

index=* sourcetype=* httpmethod=* httpstatus=*
| table clientip,httpmethod,statuscode,sessionid
| eval mv_field = clientip.”,”.httpmethod”,”.statuscode”,”.sessionid
| makemv delim=”,” mv_field
| table mv_field

 




clientIP

HTTPMETHOD

STATUS CODE

SESSION

clientIP 1

GET
POST
HEAD

200s
400s
300s
500s

sessionid

clientIP 2

POST

400s
200s

sessionid

clientIP 3

GET
POST

200S

sessionid



Labels (1)
Tags (2)
0 Karma
1 Solution

johnhuang
Motivator

Based on the example output you provided:

 

index=* sourcetype=* httpmethod=* httpstatus=*
| stats values(*) AS * BY clientip
| table clientip,httpmethod,statuscode,sessionid

 

View solution in original post

Win
Explorer

@johnhuang . Thank you. This worked perfectly as I wanted

johnhuang
Motivator

Based on the example output you provided:

 

index=* sourcetype=* httpmethod=* httpstatus=*
| stats values(*) AS * BY clientip
| table clientip,httpmethod,statuscode,sessionid

 

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...