Splunk Search

How to search a specific user's internet activity for a certain time range? (websites visited, search history, timestamps)

RobertKepner
New Member

I am trying to complete a request for a specific employees internet search history. I need to specify a date range, list all websites visited, and the time the searches occurred. I can't seem to get the search string right, any help would be appreciated.

0 Karma

Jarohnimo
Builder

If it's IIS just grab the ur_stem="*" and whatever is the parsed field for username and then table the results by those same fields ... also include _time

0 Karma

Richfez
SplunkTrust
SplunkTrust

A quick look at the fortigate log documentation says this probably is possible, but so much depends on exactly how you have the device(s) configured, if you have the Splunk Fortigate App installed and so on.

If you could please describe and provide a few examples of what logs you have available and perhaps what search you have that isn't working, we could potentially help you with this.

0 Karma

woodcock
Esteemed Legend

Show a sample log and maybe we can get on with helping.

0 Karma

saurabh_tek
Communicator

Hello @RobertKepner - did you manage to get this done ?

@sundareshr @woodcock
I wanted to check - if fortigate logs would be enough to get this done or something else would also be needed ?
I am also planning to achieve the same. i think if i shall make a search query out of fortigate data, i should be able to achieve this..

0 Karma

woodcock
Esteemed Legend

I am not familiar what those logs so I cannot say.

0 Karma

sundareshr
Legend

@saurabh_tek I am not familiar with the fortigate data either. If you can share a couple of events with extracted field names, we can help.

0 Karma

sundareshr
Legend

It would help some of the raw data and/or your current search.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...