Splunk Search

Extract search window for all types searches run in splunk

kapadiamayur
New Member

I want to run a query to extract all the searches that have been run in splunk , to identity search date ranges provided on them by users, adhoc searches etc.

So if if search on 1st of month, then i am expecting to get following information.

300 searches run with search window of <=1 day
20 searches run with search window of > 1day & <=1 week.
4 searches run with search window > 1 week <= 1month
100 all time searches.

0 Karma

logloganathan
Motivator

Could you please try to run the below query

index=_audit action=search info=granted search=* NOT "search_id='scheduler" NOT "search='|history" NOT "user=splunk-system-user" NOT "search='typeahead" NOT "search='| metadata type=sourcetypes | search totalCount > 0"
| stats count by search _time

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...