Splunk Search

Update Time Field for a User on Table

aquinojason
Path Finder

Hi,

I am making a report that needs to identify how long long since a user launch an application. Can I use splunk to do this instead?

We have a tool that can generate the Username Fullname 

I am thinking to add the "date" of when the report was generated as "last used date"

so the file would look like:

user123,fullusername,dateofreport

and by the next time (after a week), if the user exists on the table, the dateofreport would be updated.

and then after 3 months or so of data, I need to generate another report of the users who didn't open the application for the last 3 months.

 

Thanks for the help.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Something like this?

| stats last(dateofreport) as lastreport by userid

aquinojason
Path Finder

Hi,

Thanks for the idea. I'll test this one.

Regards,

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...