Splunk Search

Analyze user interaction with splunk?

marcogallotta
Explorer

I am looking for a solution to present analytics of user interaction logs, e.g. number of times an action was performed, time between actions, etc. Is it possible to achieve this with splunk? I'm basically trying to achieve similar to what flurry does for mobile apps, but for server-side interaction.

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

I'm not familiar with flurry but yes these are possible to achieve with Splunk. It will all depend on the level of detail in the user interaction logs. If the data is there, splunk can help you analyze it.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Your events do not have a timestamp anywhere in them? How can you analyze time if they don't have that data? Look at the transaction command because that is what will help you look at time between events. Show us some sample events, you can edit your question above.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/transaction

0 Karma

marcogallotta
Explorer

After reading more about splunk, it appears splunk works best with data that has a timestamp which becomes the x access. I can't seem to work out how to analyze time between events (e.g. session duration), ratio between the count of two events (e.g. invite sent and invite accepted) or sum of non-unit amounts (e.g. total money spent). I am producing the interaction logs, so I can always add more detail, but I'm not sure splunk can help me analyse it in the way I'm looking for it to.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...