Getting Data In

Total users logged in at any given time to a Windows machine

tkerr1357
Path Finder

Hello all,

I am fairly new to Splunk and am working on gathering data for our operations team. They are asking me to create a dashboard for them with relevant login/logoff security data. The part that has me stumped is getting the exact number of active users on a given machine at any time. This would normally be accomplished by launching the command line and just running query user. Any help on this one would be greatly appreciated.

Tags (2)
0 Karma

BainM
Communicator

HI tkerr1357-

You will want to use an add-on like the Splunk for Windows Add-On. This allows you to collect and index Windows events from the target server to search against. You would then search for the logon/off Window event.

App:
https://splunkbase.splunk.com/app/742/#/details
Docs:
https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows

And here's a nice front-end companion app to the backend app with dashboards and sample queries:
https://splunkbase.splunk.com/app/1680/

Hope this helps,
Mike

0 Karma

tkerr1357
Path Finder

Hi Mike, we do make use of that app however there are far more logon events then we have active users in our system at any given time. I was searching based on EventCode=4624 which is a successful logon event. Do I need to do some kind of search of successful login events and then exclude users that have logoff events within like 30 seconds or so to find total users that are logged in? if so not sure how to drill up a search like that so anything that could point in the right direction would be helpful. I will continue to review the doc's for now.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...