Splunk Search

Chart count by Duration and User name

strueblood
Explorer

I have pulled VPN logs and I'd like to report on the duration that a user has used the VPN tunnel.

I have found the event that shows a disconnected VPN session.

It has the duration information and the user name. I don't know how to create a chart that will include the user name and the duration to next to it.

I have Chart by count Duration (Duration is a field I created)

But I can't seem to put in a search string to show Username and duration next to it.

Tags (1)
0 Karma

strueblood
Explorer

That is a very good answer, that answers half my question.

I'm now getting data showing, but I want the duration next to the user name, I'm getting the duration over the top and the count next to the user name.

What would I put instead of count?

0 Karma

ftk
Motivator

I edited my answer. Have a look.

0 Karma

ftk
Motivator

You could try doing something like:

your search | chart count Username by Duration
0 Karma

strueblood
Explorer

That didn't error out but comes up with zero data. Yes, I to show a bar graph that shows user name and the duration graph next to it.

0 Karma

ftk
Motivator

Hmm, here is another edit. Lemme see if I get this right -- You want a chart (column chart?) that will show a Username and its associated duration? Or do you mean a table?

0 Karma

strueblood
Explorer

Sorry, I get this error message.

Error in 'chart' command: The specifier 'Duration' is invalid. It must be in form (). For example: max(size).

I get where you are going and I hope it can be that simple, other ideas?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...