Splunk Enterprise

How to create a search in dashboard that show the time, user, hostname, and URL a list of users are visiting?

tlcconsulting
Loves-to-Learn Lots

How do I create a search that would display:

The time, user, hostname, and URL those a list of users are visiting.

Labels (1)
Tags (2)
0 Karma

tlcconsulting
Loves-to-Learn Lots

Not understanding what you're asking for.  Are you looking for indexers, source/sourcetype.. etc ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The events themselves, for example, lines from a log that has been ingested - how you identify users, url, host - or do you already have these fields?

| table _time hostname user url

 

0 Karma

tlcconsulting
Loves-to-Learn Lots

I have a list of host name I want to search.  Basically, with these users, i will to be able to search on what URL's they go to.  when they go to them...etc.  This is in a secure environment.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Start with some training/tutorials, or perhaps some of the example dashboards and see how you can adapt them to your situation.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share a sample of the events you have ingested into splunk?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...