How to know the number of accounts that do have not login in over 30 days in application1 but have login in application2
I don't know the fields you have in your logs, so I'll assume that you have the following fields app and username and sourcetype is applogs, so you can make the following searches (and from time picker choose last month):
sourcetype=applogs app=application1 | stats count by user
sourcetype=applogs app=application2 | stats count by user
hope that this help ..
I'd do this like so:
sourcetype=app_a OR sourcetype=app_b | stats values(sourcetype) as sourcetypes dc(sourcetype) as apps by user | where sourcetypes=="app_a" AND apps=1
How to right search query to know last login and password reset for (2 applications) application 1 and application2
Need to write query with below given index and source
index=ibm source="abmom-tail://ibmarehouse/ibm_account
I don't know the fields you have in your logs, so I'll assume that you have the following fields app and username and sourcetype is applogs, so you can make the following searches (and from time picker choose last month):
sourcetype=applogs app=application1 | stats count by user
sourcetype=applogs app=application2 | stats count by user
hope that this help ..
Please helpme out of it
How to right search query to know last login and password reset for (2 applications) application 1 and application2
Need to write query with below given index and source
index=ibm source="abmom-tail://ibmarehouse/ibm_account