Splunk Search

User with name per most used application

Gib10920
New Member

I want to run a query on a server to display all users with their names per application. It is about finding out which users need which program most on a particular server. However, I have no idea how I could write such a script. Can someone help me, please!

Labels (2)
0 Karma

alonsocaio
Contributor

Hi,

If you want to list which users are using each application, maybe the "| stats values()" can be useful:

 

...
| stats values(username) by application

 

Also, if you don't mind, you can share any query you have already tried so I can help you to to include the stats command.

 

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...