All Apps and Add-ons

truncated graph "User logon failure"

nicolas_rofort
Explorer

I have truncated graph in dashboards "User Logon Failures" and "User Utilization" (does not show all data). When I launch the search command in search view, it's work well.

0 Karma
1 Solution

nicolas_rofort
Explorer

I find a solution. There's a limit (10000 events) with module, so I modify the search (file sec_logon_fail.xml) with bucket and stats to solve this problem.

View solution in original post

0 Karma

nicolas_rofort
Explorer

I find a solution. There's a limit (10000 events) with module, so I modify the search (file sec_logon_fail.xml) with bucket and stats to solve this problem.

0 Karma

linu1988
Champion

please mark it as the answer if it worked for you

0 Karma
Get Updates on the Splunk Community!

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...