Splunk search for Apps and Views that Users are Accessing

Copy
index=_internal earliest=@d latest=now | stats latest(_time) as _time, values(view) as view, values(app) as app, values(uri) as uri by user
This search will output a table showing what views, apps and uri's have been accessed by users within your Splunk environment for the current day.
0 comments

Category:

General Splunk


Tags:

administration users audit

Search Commands:

Sign in or Register to submit a comment