Splunk Enterprise Security

How to create a table to display different users who logged in from same clientip?

Win
Explorer

Hi, I am a student and new to Splunk. I really need help creating a table like this:

The goal is to detect different users that authenticated using same clientIP, different httpmethod, different status codes, and its equivalent sessionid. I used the below query, which yielded no results.

 

index=* sourcetype=* httpmethod=* httpstatus=*
| table clientip,httpmethod,statuscode,sessionid
| eval mv_field = clientip.”,”.httpmethod”,”.statuscode”,”.sessionid
| makemv delim=”,” mv_field
| table mv_field

 




clientIP

HTTPMETHOD

STATUS CODE

SESSION

clientIP 1

GET
POST
HEAD

200s
400s
300s
500s

sessionid

clientIP 2

POST

400s
200s

sessionid

clientIP 3

GET
POST

200S

sessionid



Labels (1)
Tags (2)
0 Karma
1 Solution

johnhuang
Motivator

Based on the example output you provided:

 

index=* sourcetype=* httpmethod=* httpstatus=*
| stats values(*) AS * BY clientip
| table clientip,httpmethod,statuscode,sessionid

 

View solution in original post

Win
Explorer

@johnhuang . Thank you. This worked perfectly as I wanted

johnhuang
Motivator

Based on the example output you provided:

 

index=* sourcetype=* httpmethod=* httpstatus=*
| stats values(*) AS * BY clientip
| table clientip,httpmethod,statuscode,sessionid

 

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...