Security

search for Count of users per minute for a hour

ma_anand1984
Contributor

user activities are captured in _audit index. Using this i would like to see how many users are active on a given minute for an hour. I tried this

index=_audit | dedup user | timechart span = "1m" count(user)

but dedup worked on the whole time frame instead of every minute. Any help would be appreciated.

0 Karma
1 Solution

ma_anand1984
Contributor

This is the answer for the requirement i had
index=_audit | timechart span="1m" dc(user)| rename dc(user) as "Concurrent User"

View solution in original post

ma_anand1984
Contributor

This is the answer for the requirement i had
index=_audit | timechart span="1m" dc(user)| rename dc(user) as "Concurrent User"

sdaniels
Splunk Employee
Splunk Employee

Did this work for you?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

What if you do the following:

... | bucket span=1m _time | dedup user, _time | timechart ...

ma_anand1984
Contributor

I want some thing like this

time user count
1m 5
2m 3
3m 20

etc

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...