Splunk Query to report on users logging on to the Splunk Web Console _internal/ audittrail/ splunkd Suren Vote Up +9 Vote Down -1You already voted! index=_audit tag=authentication info=succeeded |dedup user | table user timestamp Share This: Tagged: Splunk Logon Audit