Splunk Search

How to show an IP is associated with multiple usernames

alexrod03
New Member

I have one source type and 2 field values, username and IP.
How do I show IP that is associated with multiple usernames.

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@alexrod03,
Try

your search |stats dc(username) as count,values(username) as usernames by IP | where count > 1

View solution in original post

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@alexrod03,
Try

your search |stats dc(username) as count,values(username) as usernames by IP | where count > 1

View solution in original post

0 Karma

alexrod03
New Member

That worked great. Thanks

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!