I want to run a query to extract all the searches that have been run in splunk , to identity search date ranges provided on them by users, adhoc searches etc.
So if if search on 1st of month, then i am expecting to get following information.
300 searches run with search window of <=1 day
20 searches run with search window of > 1day & <=1 week.
4 searches run with search window > 1 week <= 1month
100 all time searches.
Could you please try to run the below query
index=_audit action=search info=granted search=* NOT "search_id='scheduler" NOT "search='|history" NOT "user=splunk-system-user" NOT "search='typeahead" NOT "search='| metadata type=sourcetypes | search totalCount > 0"
| stats count by search _time