Splunk Search

search for unique userid in one hour window

dominiquevocat
SplunkTrust
SplunkTrust

I am trying to report the number of unique logged in users (field=USERNAME) in a timespan=1h and since i only want unique users i probably should use dedup but when i run this search for a day or week there is a chance that the same user logged in on several days in that timespan so the dedup should affect only the events within the timespan.

say
index="xxx" | timechart span=1h sum(USERNAME) | dedup USERNAME
is not right. Deduping after that is no use.

Also i would like to have the top number of concurent (see where this goes?) Users in a 1h timespan for a report.

How would i best go about it in a search? How can i report this concurent users max per 1h timespan?

Tags (1)
0 Karma
1 Solution

Ayn
Legend

I don't really understand all of your question, but I'll try to respond according to what I think you're asking.

For a given 1 hour interval, you want to see the distinct count of users that generated events during that timespan. For this, use stats distinct_count (or dc which is the short version).

index="xxx" | timechart span=1h dc(USERNAME)

View solution in original post

0 Karma

Ayn
Legend

I don't really understand all of your question, but I'll try to respond according to what I think you're asking.

For a given 1 hour interval, you want to see the distinct count of users that generated events during that timespan. For this, use stats distinct_count (or dc which is the short version).

index="xxx" | timechart span=1h dc(USERNAME)
0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

DistinctCount sounds nice. I think that does most of what i need.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...