- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
splunkcol
Builder
03-17-2021
09:33 AM
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

manjunathmeti
Champion
03-17-2021
09:46 AM
hi @splunkcol,
The below query give top users who successfully logged into Splunk in the last 1 year.
index=_audit sourcetype=audittrail action="login attempt" info=succeeded earliest=-1y | top user
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
03-17-2021
09:47 AM
Top 10 by what measure? What problem are you trying to solve?
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

manjunathmeti
Champion
03-17-2021
09:46 AM
hi @splunkcol,
The below query give top users who successfully logged into Splunk in the last 1 year.
index=_audit sourcetype=audittrail action="login attempt" info=succeeded earliest=-1y | top user
