I have a about 250 users and I would like to to know when was the last time each of them have logged in. Is there a query that I can use.
Try
index=_audit action="login attempt" | stats max(timestamp) by user
The answer of wollinet works only for the current year, because the timestamp is mm-dd-yy.
So if you did login in December 2016 and January 2017, the last login will be December 2016.
Is it possible to modify the query that the order is yy-mm-dd?
Should be like this:
iindex=_audit action="login attempt" | stats latest(user) by user
It should actually not matter what you put inside the latest()...
Try
index=_audit action="login attempt" | stats max(timestamp) by user
That works! Thanks a lot.
action="login attempt" is not logged for 6.2.2 it seems..
works for 6.1.4 Build 233537
It works ok for 6.3.
They are splunk users. I would like to know when each user last logged in Splunk.
Can you elaborate a bit please? Are they splunk users and you want to look at splunk's audit logs or are they users in a different system? If they are a different system, what system, how do you get the logs, can you provide sample data?
You'll get a better answer the more detail you provide.