Show all currently logged in users

Use this Splunk rest query to list all currently logged in users (to your Splunk server).

 

| rest /services/authentication/current-context | search NOT username=”splunk-system-user” | table username roles updated

 

Share This:
Tagged:

Comments

  1. Mark

    I am not sure what updated is supposed to do… but, it looked like something close to epoc time? Anyway, I cut it off and the query looked cleaner?

Leave A Comment?