I can search through cisco logs easily enough, and can also sort for logins, or failed logins without issue - but since the username isn't actually a field that splunk seems to automatically parse, I would love to be able to show a bar graph or pie chart that shows how many logins over the past 7 days, sorts by username.
You can do further parsing of the log and extract additional fields in your search query to find the user names.
You can do further parsing of the log and extract additional fields in your search query to find the user names.