Splunk Search

Detecting Simultaneous Sessions

Warme1980
Engager

I have an inhouse written app that outputs an audit log in the form of:

DateTime,Username,Activity,SessionID

So I'll get:

01:01:01,Fred001,Logon,001
01:01:02,Fred001,TakeOverWorld,001
01:01:03,Fred001,Logon,002
01:01:04,Fred001,Logoff,001
01:01:05,Fred001,DestroyWorld,002
01:01:06,Fred001,Logoff,002

Now obviously, aside from taking over the world (which is not against our policies) Fred has shared his password (which is) with someone who destroyed the world (also not explicitly against our policy).

So we need to talk to Fred about his blatant disregard of the simultaneous logon policy.

How do I construct a Splunk query to catch him?

Thanks!

sundareshr
Legend
0 Karma

Warme1980
Engager

Hrm, that might be the thread I need to start tugging on to get to a solution, thanks!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...