Splunk Search

How to review how many servers a user logged into within a specific time period

rcastello
Explorer

Hello,

How can I compile a stats list of what servers a user account has logged into within a specific time period? I was surprised I couldn't find a similar answer that solved this.

Thank you.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @rcastello,
try something like this (for Windows Operative Systems):

index=wineventlog EventCode=4624
| stats values(host) AS host count BY Account_name

in this way you have a list of hosts for each user.

If instead you want to search a specific account, you could run something like this

index=wineventlog EventCode=4624 Account_name="xxxxxxxx"
| stats count BY host

that you can insert in a dashboard.

In both cases, check the name of the field Account_name because it could be different in your Windows (e.g. in Italy is frequently Nome_account).

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rcastello,
try something like this (for Windows Operative Systems):

index=wineventlog EventCode=4624
| stats values(host) AS host count BY Account_name

in this way you have a list of hosts for each user.

If instead you want to search a specific account, you could run something like this

index=wineventlog EventCode=4624 Account_name="xxxxxxxx"
| stats count BY host

that you can insert in a dashboard.

In both cases, check the name of the field Account_name because it could be different in your Windows (e.g. in Italy is frequently Nome_account).

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...