Splunk Search

How can I use login and logout events for specific UserIDs to determine concurrent users at a given time?

purcell12491
Loves-to-Learn

These are the fields I'm using - Body, ATNVersion, operatingsystem, osversion, MID 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Your problem is not clearly specified. You might want to find out how many users are logged in at some given point in time or which ones are logged in (also possibly counting or not duplicate logins).

2. Do you have a separate login and logout events?

3. Remember that as you're logging only login and logout events you won't find sessions which "overlap" your search time range. For example - if your user logged in at 9am and logged out at 12pm you won't find this session if you only search through 10am-11am because you have no events regarding this session during that time range. (this problem can be alleviated for specific use cases by using summary indexing).

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @purcell12491 ,

could you beter describe your requirement: operative systems, fields used, etc...?

Ciao.

Giuseppe

0 Karma

KendallW
Contributor
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...