Splunk Search

Creating Bar Chart for SSH logs

akashjohn
Explorer

Hi Team,

We are trying to create a bar chart from secure log. The ultimate goal is to plot the accounts (top 10) used to login to maximum number of servers with count. i.e. the accounts which were used to log into multiple servers. From basic query we were are getting an output as shown below,
alt text

We are planning to plot server details (pup-ofc-mar-hjn-a) on X - Axis and users on Y - Axix. Could you please let us know how can we achieve this?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

I think that you already loaded logs in an index (e.g.: secure_logs) and extracted the requested fields (user, account, etc...).
Than you have to write a search as the following
index=secure_logs | top users
or
index=secure_logs | stats dc(host) by users | head 10

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

I think that you already loaded logs in an index (e.g.: secure_logs) and extracted the requested fields (user, account, etc...).
Than you have to write a search as the following
index=secure_logs | top users
or
index=secure_logs | stats dc(host) by users | head 10

Bye.
Giuseppe

akashjohn
Explorer

Hi Giuseppe,

Thanks for the response. we can fetch the data with the quires, but here the requirement is to plot the accounts (top 10) used to login to maximum number of servers with count. i.e. the accounts which were used to log into multiple servers.

That means we need to fetch the users which are login to multiple servers and need to find the count of servers. The query which you have mentioned is not seems to be working in this case.

0 Karma

gcusello
SplunkTrust
SplunkTrust

with this search you have the number of distict server accessed by each user.

Sorry I forgot to insert sort!
index=secure_logs | stats dc(host) AS hosts by users | sort -hosts | head 10

Bye.
Giuseppe

akashjohn
Explorer

Thanks Giuseppe, it seems to be working for me.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...