I am planning to display the distinct count of users logged into Splunk today.
I came across, following two searches :
index="_internal" source=*access.log user!="-" */app/*|stats dc(user) as user
index="_internal" sourcetype=splunk_web_access | stats dc(user) as distinct_users
Both gives me the different count. Am not sure which one is correct one.
Other alternatives are also welcome.
Thanks in advance.