Detailed User Activity

Share This:


  1. Doris

    when running this command in hopes of capturing user activity I get an error messages indicating “The regex”field” does not extract anything. It should specify at least one name group Format(?…).

    1. Jeff


      You might want to copy the search to notepad/notepad++ first as I’ve noticed in general when trying to copy/paste searches some of the special characters don’t get copied correctly.

      I copied this search to notepad++ and then copied from there to Splunk and was able to run the search

Leave A Comment?