Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Access Granted/Denied query

$
0
0
Hi, I have the following table: _time usernameOK _time usernameFail example: 2017-09-28 00:10:00 usernameOK=robE 2017-09-28 01:10:20 usernameFail=jonasH 2017-09-28 02:20:23 usernameOK=timN 2017-09-28 02:20:35 usernameOK=robE 2017-09-28 02:30:46 usernameOK=robE Basically I am trying to get the count of BOTH usernameOK and usernameFAIL, by time (bucketed 1h) by user, akin to a pivot table but my count command is coming back with an error ... Any ideas? Thank you.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>