In the Splunk 4.1 webcast earlier this week, one of the presenters showed a combined_access report that looked to produce a report of the user's IP address and then indented the URLs they viewed sorted by time. There may have been more columns.
I looked to see if their was a recording or similar question here, but didn't see anything. Does anyone know how he did that as it looked useful was seeing how people migrate through your site.
I didn't see the webcast, but I guess I would do it with something like:
sourcetype=access_combined | stats list(uri) by clientip
This could be the search:
sourcetype="access_combined" | chart count by clientip,uri
I didn't see the webcast, but I guess I would do it with something like:
sourcetype=access_combined | stats list(uri) by clientip