Splunk Search

Timechart presentation

gjhaaland
Explorer

Hi,

Not sure how to fix continius bar between login and logout. As you can see on picture it's marked as login, lot of spaces and then logout. The best would be everything is color marked from login until logout. Though it could be done throug format, but not this time.  Hope someone can help me with it

Rgds

Splunk-chart.JPG

Labels (1)
0 Karma

gjhaaland
Explorer

Thanks, but I also think it should be possible to mark everyting between login and logout in a timechart. Maybe it's not possible. If not I will investigae the apps 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can't fill anything in because you don't differentiate between the login and logout events. The first bar is not necessarily a login followed by a logout, as your first event may be a logout then a login then another logout.

You would need to make your search determine that 4624 is a start login event and the 4634 the logout or end event, rather than just doing a dc(user) which will always be 1.

I suggest you look at a couple of apps instead of timechart that are designed for this

https://splunkbase.splunk.com/app/4370

https://splunkbase.splunk.com/app/3120

 

Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...