Splunk Query to report on users logging on to the Splunk Web Console

index=_audit tag=authentication info=succeeded |dedup user | table user timestamp
Share This:

Leave A Comment?