Splunk IT Service Intelligence
Highlighted

ITSI User usage report

New Member

Hi, need some expert help tuning a search query focused only on ITSI users per week. I have the following query but it is running really slow.

index="internal" host= app=itsi NOT user="splunk-system-user"| timechart span=1d count as countuser by user usenull=f

Any suggestions are welcomed.

Thanks.

0 Karma
Highlighted

Re: ITSI User usage report

Splunk Employee
Splunk Employee

Do you have a more specific goal you are trying to achieve aside from counting events from the itsi app by user? That will help tailor the search requirements.

0 Karma
Highlighted

Re: ITSI User usage report

New Member

Hi there. I need to track and report who logged into ITSI, either to view or create glasstables, base searches and entities etc . Thanks.

0 Karma
Highlighted

Re: ITSI User usage report

Path Finder

Try this:

index=_internal host=<insert-your-ITSI-host(s)> source="/opt/splunk/var/log/splunk/splunkd_ui_access.log" uri=*SA-ITOA/itoa_interface* 
|timechart span=1d dc(user) as users
0 Karma