Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Ever wonder which dashboards are being used and what users are using them?

$
0
0
The dashboard below should help answer that question for you. The User dropdown uses a `|rest` search to get a list of LDAP users so if you don't have access to run `| rest` or aren't using LDAP then that dropdown won't populate but the dashboard will still work fine you just won't be able to look at all dashboard usage for a single user. You can drilldown on any dashboard that shows in the chart to see the specific users that are using the dashboard per day. To go back to the main chart select the "Reset Drilldown" button. NOTE - You will need the tokenlinks.js available for the reset button to work. I got it from the 6.x Dashboard Examples App.
-14d@dnowAll Users|rest /services/authentication/users splunk_server=local |fields title type realname|rename title as userName|rename realname as Name | search type=LDAP | eval display=userName+" - "+Name | fields userName displaydisplayuserName*user= OR user=
Distinct count of users that visited each dashboard per day - (Top 25)Select a dashboard to see more info about itindex="_internal" source=*access* user!="-" $user$ source="/opt/splunk/var/log/splunk/splunkd_ui_access.log" "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search app="search" dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home" dashboard!="alerts" dashboard!="dashboards" dashboard!="reports" dashboard!="report" | bucket _time span=1d | stats dc(dashboard) as c by dashboard user _time | timechart span=1d limit=25 useother=f count by dashboard$field1.earliest$$field1.latest$$click.name2$Distinct count of users that visited each dashboard per dayindex="_internal" source=*access* user!="-" user=* "/$dashboard$?" source="/opt/splunk/var/log/splunk/splunkd_ui_access.log" "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search app="search" dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home" dashboard!="alerts" dashboard!="dashboards" dashboard!="reports" dashboard!="report" | bucket _time span=1d | stats dc(dashboard) as c by dashboard user _time | timechart span=1d limit=25 useother=f count by dashboard0Distinct users that visited $dashboard$index="_internal" user=* sourcetype=splunkd_ui_access user!="-" "/$dashboard$?" source="/opt/splunk/var/log/splunk/splunkd_ui_access.log" root="en-US" | bucket _time span=1d | stats values(user) as "Unique Users" by _time$field1.earliest$$field1.latest$

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>