What setup is required and what will be the search so that I can find out,
thanks, ronak
splunk_webaccess -> splunk_ui_access
logged in users
index=_internal sourcetype=splunkd_ui_access | dedup host user | table host user _time req_time
logged in users rolling time
index=_internal sourcetype=splunkd_ui_access | table host user _time req_time
If you have an indexer cluster -> You should have all this info in the Distributed Management Console on the Cluster Master.
where it that in DMC?
Start here
For users logged in, and search head they are in
index=_internal sourcetype=splunk_webaccess | dedup host USER | table host USER
For the searches issued..
index=_internal sourcetype=splunkd_remote_searches
Cross check the sourcetypes for the exact naming..
sourcetype of splunk_webaccess at least in 6.3.3 version isn't available..
verified 6.5.3
index=_internal sourcetype=splunkd_ui_access | dedup host user | table host user _time req_time