Splunk Enterprise Security

How to create a table to display different users who logged in from same clientip?

Win
Explorer

Hi, I am a student and new to Splunk. I really need help creating a table like this:

The goal is to detect different users that authenticated using same clientIP, different httpmethod, different status codes, and its equivalent sessionid. I used the below query, which yielded no results.

 

index=* sourcetype=* httpmethod=* httpstatus=*
| table clientip,httpmethod,statuscode,sessionid
| eval mv_field = clientip.”,”.httpmethod”,”.statuscode”,”.sessionid
| makemv delim=”,” mv_field
| table mv_field

 




clientIP

HTTPMETHOD

STATUS CODE

SESSION

clientIP 1

GET
POST
HEAD

200s
400s
300s
500s

sessionid

clientIP 2

POST

400s
200s

sessionid

clientIP 3

GET
POST

200S

sessionid



Labels (1)
Tags (2)
0 Karma
1 Solution

johnhuang
Motivator

Based on the example output you provided:

 

index=* sourcetype=* httpmethod=* httpstatus=*
| stats values(*) AS * BY clientip
| table clientip,httpmethod,statuscode,sessionid

 

View solution in original post

Win
Explorer

@johnhuang . Thank you. This worked perfectly as I wanted

johnhuang
Motivator

Based on the example output you provided:

 

index=* sourcetype=* httpmethod=* httpstatus=*
| stats values(*) AS * BY clientip
| table clientip,httpmethod,statuscode,sessionid

 

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...