Splunk Enterprise Security

how to compare successful logins in the host with yesterday's

satyaallaparthi
Communicator

Hello,

I am getting successful logins from each server which is like 4000 per day from Each server. But some days that number is going high.
How can I compare successful logins with yesterday and how to get the difference between yesterday and today?

and create a notable event which is more than normal logins by comparing 2.

Any help would be appreciated!

Thanks,

0 Karma
1 Solution

mayurr98
Super Champion

Try this logic :

index=_internal earliest=-1d@d latest=now 
| timechart count span=1d 
| timewrap d 
| rename 1day_before as Yesterday latest_day as Today 
| eval diff=Yesterday-Today

View solution in original post

mayurr98
Super Champion

Try this logic :

index=_internal earliest=-1d@d latest=now 
| timechart count span=1d 
| timewrap d 
| rename 1day_before as Yesterday latest_day as Today 
| eval diff=Yesterday-Today
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...