Dashboards & Visualizations

How to create a table that shows users connected to a specific dashboard and the number of times they viewed it?

DavidHourani
Super Champion

Hello Splunkers,

I would like to create a table that shows the users that connected to a specific dashboard and the number of times they viewed it. This is sort of an audit to make sure that the dashboard has been used and to view the users that used it the most.

Is that possible? If so, can anyone help me out and tell me how that can be achieved?

Regards,
David

0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

I built a free app for understanding Splunk usage and adoption called Search Activity which should help you do exactly what you're looking for. On the main page in the app you can view the most popular views on the most popular apps in your environment. For any user, you can view what -their- most popular views and apps are, and you can also walk back through time to see what they've done (e.g., David logged in. David browsed to MyCustomView on MyCustomApp. David launched five dashboard searches. etc.). Frankly this is an area for development in my app because of the value potential, so if you find that there's something you can't do out of the box, let me know so I can build it for you!

If you want to go it alone, check out index=_internal sourcetype=splunk_web_access. I filter for GETs where the URL is /[^/]*/app to be able understand view access.

View solution in original post

David
Splunk Employee
Splunk Employee

I built a free app for understanding Splunk usage and adoption called Search Activity which should help you do exactly what you're looking for. On the main page in the app you can view the most popular views on the most popular apps in your environment. For any user, you can view what -their- most popular views and apps are, and you can also walk back through time to see what they've done (e.g., David logged in. David browsed to MyCustomView on MyCustomApp. David launched five dashboard searches. etc.). Frankly this is an area for development in my app because of the value potential, so if you find that there's something you can't do out of the box, let me know so I can build it for you!

If you want to go it alone, check out index=_internal sourcetype=splunk_web_access. I filter for GETs where the URL is /[^/]*/app to be able understand view access.

alacercogitatus
SplunkTrust
SplunkTrust

You can! it is in the _audit index. An even faster way would be to install SoS on a Search head (Splunk on Splunk). This App has a dashboard just for this reason!

0 Karma

DavidHourani
Super Champion

Thanks mate! The thing is that with sos you can see the searches that have been run but not the dashboards that have been used and so there is no stats about dashboards usage... I would like to know if someone connected to a specific page. I will check the audit log to see if there is any info about that..

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...