Hi,
I would like to draw a chart representing number of active sessions at any given time...probably on a time chart.
The log contains three different type of log lines: Login, Log out and Expire sessions. I have come up with the following search so far, but it's not working well.
sourcetype="Engine" Server="ABC" login OR "log out" OR "removing session" | transaction UserSession | where duration=0 | timechart span=1m count(LoginDate) as in count(LogoutDate) as out count(LoginExpireDate) as expire | streamstats sum(in) as totalin sum(out) as totalout sum(expire) as totalexpire | eval totalactive=totalin-totalout-totalexpire
Thanks.
... View more