Splunk Search

How to get Splunk access statistics

snevarezh
Explorer

We need to provide Splunk user access statistics:

How many user accessed splunk the last month
How many times a specific user acceded to splunk
Top 10 users who acceced to splunk
Top 10 prefered searches

and that kind of reports

Tags (1)
1 Solution

MHibbin
Influencer

There are also some nice features in the S.o.S (Splunk on Splunk) App around user activity. It was released by Splunk and as such is also supported, it's available here http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk. Once installed you can then go to "Search >> UI and User Search Activity". It also has a load of other helpful features for troubleshooting.

View solution in original post

MHibbin
Influencer

There are also some nice features in the S.o.S (Splunk on Splunk) App around user activity. It was released by Splunk and as such is also supported, it's available here http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk. Once installed you can then go to "Search >> UI and User Search Activity". It also has a load of other helpful features for troubleshooting.

sdwilkerson
Contributor

Snvarezh,

Much of what you are looking for is part of a dashboard built-in to the search app.

  1. Go to the search app
  2. On the top navigation, click on status|search activity and look the the data returned by the listed dashboards

Beyond what is there, you can click on view results to get more detail or otherwise tweak the search to more specifically find what you need.

Best,
Sean

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...