Hi, need some expert help tuning a search query focused only on ITSI users per week. I have the following query but it is running really slow.
index="_internal" host= app=itsi NOT user="splunk-system-user"| timechart span=1d count as count_user by user usenull=f
Any suggestions are welcomed.
Thanks.
Try this:
index=_internal host=<insert-your-ITSI-host(s)> source="/opt/splunk/var/log/splunk/splunkd_ui_access.log" uri=*SA-ITOA/itoa_interface*
|timechart span=1d dc(user) as users
Do you have a more specific goal you are trying to achieve aside from counting events from the itsi app by user? That will help tailor the search requirements.
Hi there. I need to track and report who logged into ITSI, either to view or create glasstables, base searches and entities etc . Thanks.