Splunk Search

Simple Search

nebel
Communicator

Hi there,

maybe its not my day today, struggeling since hours with this case 😉

Per User means one connection. Now I want to count them and bring them into a timechart.

Event:
user
peter
frank
marcus

Every 10 minutes I get a event with the Users. Now I want to count them (3) and display the amount of connections in a timechart.

Thank you very much

Regards

Tags (1)
0 Karma
1 Solution

nebel
Communicator

index=user_db earliest=-24h | multikv fields user | timechart span=10m count AS Connections

View solution in original post

0 Karma

nebel
Communicator

index=user_db earliest=-24h | multikv fields user | timechart span=10m count AS Connections

0 Karma

nebel
Communicator

I built the following search:

index=user_db | multikv fields user | timechart span=10m count by user

it works, but I don't want to display single user in my graph, only the amount of connections. How can I realize that?

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...