Splunk Search

Looking for a search that will provide the duration of time a VPN user was seen online

bluemarvel
Path Finder

The search should provide the time period in which the user was logged through VPN and possibly when the IP lease is up.

0 Karma

anthonymelita
Contributor

Take a look at the transaction command. You select one or more fields to key on and your search merges the matching events into a single transaction and auto-calculates duration. There are a handful of optional arguments for tuning as well to do stuff like limit or capture gaps in events.
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction

0 Karma

niketn
Legend

@bluemarvel, community members will be able to assist you with your query if you provide more details of what your VPN data looks like in case user logs in or logs out (this should include timestamp, unique ID for logged in user and field indicating Login and Logout).

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

nickhills
Ultra Champion

Can yougive us some sample logs, or at least a clue as to what the vpn solution is?

If my comment helps, please give it a thumbs up!
0 Karma

bluemarvel
Path Finder

below is the query

index=enterprise sourcetype="callzone:vpn" source="/var/log/vpn.log" "virtual IP" | streamstats current=f global=f window=1 last(_time) as last_ts | eval time_since_last = _time - last_ts | fieldformat time_since_last = tostring(time_since_last, "duration")

I would like to gage the duration of how long the user-VPN IP was online , this query is not working to the extent i would like

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...