Splunk Search

Calculating Active User's

apalen
Path Finder

I am struggling to find how to write this query to calculate active user's on our system. Currently we have a syslog that logs log in's and log outs. The syslog is on the same host (if that matters) we have a 2nd host that does session time outs which i also want to track as a log out.
I can pull these individually and put them into a time chart easy enough, but combining them has been futile so far.

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Try this: (I am not about your exact requirement, just generating combined count for both syslogs)

| multisearch [search logout requested | eval type="syslog"][search user in session | eval type="sessionlog"] | timechart count by type

View solution in original post

somesoni2
Revered Legend

Try this: (I am not about your exact requirement, just generating combined count for both syslogs)

| multisearch [search logout requested | eval type="syslog"][search user in session | eval type="sessionlog"] | timechart count by type

apalen
Path Finder

Thanks, This is defiantly a step in the right direction, i just need to put in the correct arguments. Im not a programer by any means, so this is quite the struggle for me. I'll keep playing with this try to make some progress.

0 Karma

apalen
Path Finder

logout requested | timechart count
user in session | timechart count

I hope this helps!

Edit: a word

0 Karma

somesoni2
Revered Legend

Could you provide sample logs or individual queries that you're using?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...