Splunk Query to report on users logging on to the Splunk Web Console _internal/ audittrail/ splunkd Suren 5 0 index=_audit tag=authentication info=succeeded |dedup user | table user timestamp 1 index=_audit tag=authentication info=succeeded |dedup user | table user timestamp Continue Reading →