Follow the steps in this recipe to leverage report acceleration to display the maximum number of concurrent sessions over time:
- Log in to your Splunk server.
- Select the Operational Intelligence application.
- From the search bar, enter the following search and select to run over Last 7 days:
index=main sourcetype=log4j | timechart span=1m dc(sessionId) AS concurrent_sessions | timechart span=30m max(concurrent_sessions) AS max_concurrent_sessions
- You might find that the search takes about 2-3 minutes to run if you have 7 days of generated data. Splunk should now display the results of the search, similar to the results shown here:
- Click on the Save As dropdown and select Report from the list:
- In the pop-up box that ...