Splunk Search

Search that shows first and last event time + total count of events per user

snix
Communicator

I have a list of top 10 users that failed to login to a site and I want to take the events related to those top ten users and get a read out of:
Time of first event
Time of last event
Total number of events

This would be relating to each user in that top ten list. Here is an example of what it would look like on paper:
---user_email--------------Start--------------------------------Stop----------------------------------Total
1. bob@bob.com---------02/28/17 - 01:16:19:PM-------09/22/17 - 10:36:51:AM---------35
2. smith@smith.com-----04/1/17 - 05:32:15:PM --------06/26/17 - 11:22:06:PM---------7

Here is what I have so far, really I am just missing how I can get the total number of events per user column:
index="test" Event_ID="123456" [search index="test"Event_ID="123456" | top limit=10 user_email | table user_email]
| stats earliest(_time) as start, latest(_time) as stop by user_email
| eval start=strftime(start, "%m/%d/%y - %I:%M:%S:%p")
| eval stop=strftime(stop, "%m/%d/%y - %I:%M:%S:%p")

0 Karma
1 Solution

sbbadri
Motivator

@snix

try this,

index=test Event_ID="123456" [search index="test"Event_ID="123456" | top limit=10 user_email | table user_email] | stats count as Total , earliest(_time) as start, latest(_time) as stop by user_email | eval start=strftime(start, "%m/%d/%y - %I:%M:%S:%p") | eval stop=strftime(stop, "%m/%d/%y - %I:%M:%S:%p") | table user_email start stop Total

View solution in original post

0 Karma

snix
Communicator

@sbbadri

That did the trick!!! Thank you!!!

0 Karma

sbbadri
Motivator

@snix

try this,

index=test Event_ID="123456" [search index="test"Event_ID="123456" | top limit=10 user_email | table user_email] | stats count as Total , earliest(_time) as start, latest(_time) as stop by user_email | eval start=strftime(start, "%m/%d/%y - %I:%M:%S:%p") | eval stop=strftime(stop, "%m/%d/%y - %I:%M:%S:%p") | table user_email start stop Total

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...