Top 10 most active Users in Linux

The following splunk query example will return the top 10 most active users in a given time range

 

sourcetype=linux_secure | rex "\suser[^'](?<User>\S+\w+)" | top limit=10 User
Share This:

Leave A Comment?