Quantcast
Channel: Questions Tagged With user
Viewing all articles
Browse latest Browse all 118

Identify User Logged Out From Inactivity

$
0
0

Hi all, we are looking at Splunk as a potential source to identify users that have long periods of inactivity. If there is no formal "logged out" or "timed out" message to queue on in the logs, would there be some way to determine time between last activity and then after a specified period of inactivity, the user is considered "logged out by inactivity" and added to a report that will be sent daily? Is this within Splunk's capabilities? If so, would this require any special scripting beyond a complex search?

I know this is pretty vague and I don't have a lot of specifics yet, but just wanted to throw it out and get some initial feedback. I'll provide updates as things progress.

Thanks


Viewing all articles
Browse latest Browse all 118

Trending Articles