Internal Splunk User Stats _internal SplunkNinja Vote Up +4 Vote Down -2You already voted! This simple Splunk query will show us unique Splunk user logged into Splunk per day, as well as total count of log-ons. index=_audit info=succeeded | timechart span=1d dc(user) as unique_users count(user) as logons_all_users Share This: Tagged: _auditinternalsplunk on splunktroubleshooting