Splunk Search

How to search for which users were logged in to a machine at a certain time or date on linux given the workstation name ?

ibrahima
New Member

I have the workstation name and IP address — how do I find out which users were logged in to the machine (Linux) and Windows, if possible?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What data from that machine does Splunk have? Are you indexing the audit log? Maybe the 'who' command from the Linux TA? It's hard to answer this question without knowing what there is to work with.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ibrahima
New Member

Yes I am indexing audit logs.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...