Skip to content

Instantly share code, notes, and snippets.

What would you like to do?
Splunk Search Query - Most Request Resource By User
stats count by user fqdn
| eventstats sum(count) as count_by_user by user
| eval percent=count/count_by_user
| table user, fqdn, percent, count, count_by_user
| sort - percent
| search count_by_user > 100
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment