Splunk Search

How to search a list of users who have tried to log in often or never logged in?

vinodsinha
Explorer

Hi,

Is there any search to get a list of users who have tried to log in often or never logged in?

Thanks,

V

0 Karma

chimell
Motivator

hi
try this

|set intersect[|rest /services/authentication/users|fields username][search NOT[ search index=_internal (sourcetype=splunk_web_access OR sourcetype=splunkd_access) | fields username ]]
0 Karma

skoelpin
SplunkTrust
SplunkTrust

I would suggest creating a field for users who logged in then create another field for users who logged out then do a ...| stats count by

To make the fields you will need to find a pattern then write a regular expression to capture this.. Post some a sample and I'll help write your regular expression

0 Karma

vinodsinha
Explorer

similar like this query but without csv option:-

| inputcsv allusers.csv | search NOT [ search index=_internal (sourcetype=splunk_web_access OR sourcetype=splunkd_access) | fields user | dedup user ]

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm looking for the data sample (Also known as events) which are returned when you run a query. It's impossible to create a regular expression without seeing the patterns in the data sample..

An example would be this

2/19/2016 12:01:00 - User gollam logged in 
2/19/2016 12:34:01 - User gollam logged out 
0 Karma

vinodsinha
Explorer

give me any simple query.

0 Karma

vinodsinha
Explorer

can you give me regular exp to run the query?

0 Karma

vinodsinha
Explorer

something like this :-
index=_internal sourcetype=splunk_web_access | table user | dedup user

0 Karma

skoelpin
SplunkTrust
SplunkTrust

If you provide a data sample..

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...