Splunk Search

Update Time Field for a User on Table

aquinojason
Path Finder

Hi,

I am making a report that needs to identify how long long since a user launch an application. Can I use splunk to do this instead?

We have a tool that can generate the Username Fullname 

I am thinking to add the "date" of when the report was generated as "last used date"

so the file would look like:

user123,fullusername,dateofreport

and by the next time (after a week), if the user exists on the table, the dateofreport would be updated.

and then after 3 months or so of data, I need to generate another report of the users who didn't open the application for the last 3 months.

 

Thanks for the help.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Something like this?

| stats last(dateofreport) as lastreport by userid

aquinojason
Path Finder

Hi,

Thanks for the idea. I'll test this one.

Regards,

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...