Security

First Day of Login / Last Day of Login in a month

karambaz
New Member

Here is the scenario:

We want to know the first day of login and the last day of login in a month for a particular user.

Please help me.

Tags (2)
0 Karma

asimagu
Builder
stats first(_time) last(_time) count(eventid) by eventid,snarehost,access,username

note that in Splunk, first is last and last is first

if you have the date of login extracted in a field, use that field instead of _time

0 Karma

MHibbin
Influencer

... pastebin?

0 Karma

karambaz
New Member

yes sir..im unable to upload the excel outcome. Can you give ur email add so i can email to you the excel sheets. In order to be more clearer.

Thanks

0 Karma

jtworzydlo
Path Finder

If I understand properly, the excel file is your outcome, and what form has the input?
To find first/last occurrence of something I would use streamstats with first()/last() function.

0 Karma

karambaz
New Member

Hi in the excel sheet there will be 4 column which will be Event ID, First Day of Login, Last Day of Login, User ID and Number of Events,

I manage to create the Event ID, User and Number of Events by using stats count by eventid,snarehost, access, username,

BUT I'm unable to include the First Time of login and the last login during the month query.

Hope you have a clear view on this. Thanks

0 Karma

jtworzydlo
Path Finder

Could you provide some more data? Maybe some example log data to work on?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...