Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

testing for the occurrence of a user

$
0
0

Hi,

I need to check to see if a list of users (150+) have logged in recently. The data comes in via syslog, and I've been able to extract the usernames from the syslog. I created a lookup file that contains just the usernames. How can I validate that these people have logged in? I can run a search that extracts the syslog messages, but how do I validate it against the lookup table? Or am I going about this all wrong?


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>