Splunk Search

Chart count by Duration and User name

strueblood
Explorer

I have pulled VPN logs and I'd like to report on the duration that a user has used the VPN tunnel.

I have found the event that shows a disconnected VPN session.

It has the duration information and the user name. I don't know how to create a chart that will include the user name and the duration to next to it.

I have Chart by count Duration (Duration is a field I created)

But I can't seem to put in a search string to show Username and duration next to it.

Tags (1)
0 Karma

strueblood
Explorer

That is a very good answer, that answers half my question.

I'm now getting data showing, but I want the duration next to the user name, I'm getting the duration over the top and the count next to the user name.

What would I put instead of count?

0 Karma

ftk
Motivator

I edited my answer. Have a look.

0 Karma

ftk
Motivator

You could try doing something like:

your search | chart count Username by Duration
0 Karma

strueblood
Explorer

That didn't error out but comes up with zero data. Yes, I to show a bar graph that shows user name and the duration graph next to it.

0 Karma

ftk
Motivator

Hmm, here is another edit. Lemme see if I get this right -- You want a chart (column chart?) that will show a Username and its associated duration? Or do you mean a table?

0 Karma

strueblood
Explorer

Sorry, I get this error message.

Error in 'chart' command: The specifier 'Duration' is invalid. It must be in form (). For example: max(size).

I get where you are going and I hope it can be that simple, other ideas?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...