Splunk Search

Calculating Active User's

apalen
Path Finder

I am struggling to find how to write this query to calculate active user's on our system. Currently we have a syslog that logs log in's and log outs. The syslog is on the same host (if that matters) we have a 2nd host that does session time outs which i also want to track as a log out.
I can pull these individually and put them into a time chart easy enough, but combining them has been futile so far.

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Try this: (I am not about your exact requirement, just generating combined count for both syslogs)

| multisearch [search logout requested | eval type="syslog"][search user in session | eval type="sessionlog"] | timechart count by type

View solution in original post

somesoni2
Revered Legend

Try this: (I am not about your exact requirement, just generating combined count for both syslogs)

| multisearch [search logout requested | eval type="syslog"][search user in session | eval type="sessionlog"] | timechart count by type

apalen
Path Finder

Thanks, This is defiantly a step in the right direction, i just need to put in the correct arguments. Im not a programer by any means, so this is quite the struggle for me. I'll keep playing with this try to make some progress.

0 Karma

apalen
Path Finder

logout requested | timechart count
user in session | timechart count

I hope this helps!

Edit: a word

0 Karma

somesoni2
Revered Legend

Could you provide sample logs or individual queries that you're using?

0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...