I have setup a splunk server and one lightforwarder client. This is configured to send the output of ps every 30 seconds to the server.
On our applications servers, I can easily count the number of connected users with the output of "ps -ef | grep | wc -l". I'd like to be able to use splunk to report this information, something like a report we run weekly (or is generated) showing the maximum number of connections on each day to the server(s).
I'm guessing it's a basic question, but any help getting started with this is appreciated !