Splunk Search

How to create a dashboard search to output these specific fields in results?

sujith0311
New Member

What I'm trying to do is when I give input as index=sftp USER=gradydftsftp and it gives output as:

Jan 27 10:15:01 wmcloudsftp internal-sftp[9055]: session closed for local user gradydftsftpdata.
Jan 27 09:15:03 wmcloudsftp internal-sftp[4534]: session closed for local user gradydftsftpdata

So my question is, how can I create a dashboard with a search which displays
file name, uploadby, uploadtime, download, downloadby, and download time.

Filename is something like (9055)
uploadby is gradydftsftp
uploadtime is 09:15:03

0 Karma

GregZillgitt
Path Finder

Are you asking how to create a search that extracts fields from your events, or how to display the output of the search in a dashboard? Or both?

Obviously the logging you've shown is not sufficient to distinguish between uploads and downloads.

0 Karma

somesoni2
Revered Legend

From the logs, how can we differentiate if its and upload or download?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...