Internal Splunk User Stats

This simple Splunk query will show us unique Splunk user logged into Splunk per day, as well as total count of log-ons.

index=_audit info=succeeded | timechart span=1d dc(user) as unique_users count(user) as logons_all_users
Share This:

Leave A Comment?