Splunk Search

Extract search window for all types searches run in splunk

kapadiamayur
New Member

I want to run a query to extract all the searches that have been run in splunk , to identity search date ranges provided on them by users, adhoc searches etc.

So if if search on 1st of month, then i am expecting to get following information.

300 searches run with search window of <=1 day
20 searches run with search window of > 1day & <=1 week.
4 searches run with search window > 1 week <= 1month
100 all time searches.

0 Karma

logloganathan
Motivator

Could you please try to run the below query

index=_audit action=search info=granted search=* NOT "search_id='scheduler" NOT "search='|history" NOT "user=splunk-system-user" NOT "search='typeahead" NOT "search='| metadata type=sourcetypes | search totalCount > 0"
| stats count by search _time

0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...