Splunk Search

Update Time Field for a User on Table

aquinojason
Path Finder

Hi,

I am making a report that needs to identify how long long since a user launch an application. Can I use splunk to do this instead?

We have a tool that can generate the Username Fullname 

I am thinking to add the "date" of when the report was generated as "last used date"

so the file would look like:

user123,fullusername,dateofreport

and by the next time (after a week), if the user exists on the table, the dateofreport would be updated.

and then after 3 months or so of data, I need to generate another report of the users who didn't open the application for the last 3 months.

 

Thanks for the help.

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Something like this?

| stats last(dateofreport) as lastreport by userid

aquinojason
Path Finder

Hi,

Thanks for the idea. I'll test this one.

Regards,

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...