Splunk Search

Username Search

gharpe2
Explorer

How do I conduct a search for unique usernames and get a count of how many people are logged on at any given time?

Tags (2)
0 Karma

piebob
Splunk Employee
Splunk Employee

for the unique usernames, you could search for usernames and then pipe to the 'uniq' command:
http://www.splunk.com/base/Documentation/latest/SearchReference/Uniq

for the count of users logged in, you can use the stats command with the count function:

http://www.splunk.com/base/Documentation/latest/SearchReference/Stats

and

http://www.splunk.com/base/Documentation/latest/SearchReference/CommonStatsFunctions

you might find the Splunk tutorial helpful in general:
http://www.splunk.com/base/Documentation/latest/User/WelcometotheSplunktutorial

Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...