Splunk Search

How to create a dashboard search to output these specific fields in results?

sujith0311
New Member

What I'm trying to do is when I give input as index=sftp USER=gradydftsftp and it gives output as:

Jan 27 10:15:01 wmcloudsftp internal-sftp[9055]: session closed for local user gradydftsftpdata.
Jan 27 09:15:03 wmcloudsftp internal-sftp[4534]: session closed for local user gradydftsftpdata

So my question is, how can I create a dashboard with a search which displays
file name, uploadby, uploadtime, download, downloadby, and download time.

Filename is something like (9055)
uploadby is gradydftsftp
uploadtime is 09:15:03

0 Karma

GregZillgitt
Path Finder

Are you asking how to create a search that extracts fields from your events, or how to display the output of the search in a dashboard? Or both?

Obviously the logging you've shown is not sufficient to distinguish between uploads and downloads.

0 Karma

somesoni2
Revered Legend

From the logs, how can we differentiate if its and upload or download?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...