Splunk Search
Highlighted

How to find which hosts a particular user has logged in to?

New Member

I'm trying to find which hosts a particular user has logged in to. I have the user's name, but I cannot figure out the systems they have used.

0 Karma
Highlighted

Re: How to find which hosts a particular user has logged in to?

Splunk Employee
Splunk Employee

Have you tried creating a table with the username and host field? The field name for username, login message, and host may differ in your situation.

Example:
'Successful-login-message' | table _time username host

0 Karma
Highlighted

Re: How to find which hosts a particular user has logged in to?

New Member

I have not tried that yet. Thank you for the suggestion.

0 Karma