Skip to content

Instantly share code, notes, and snippets.

@faststeak
Last active January 4, 2018 16:20
Show Gist options
  • Save faststeak/66768507a3c2f7833ca3aad0f6d6b557 to your computer and use it in GitHub Desktop.
Save faststeak/66768507a3c2f7833ca3aad0f6d6b557 to your computer and use it in GitHub Desktop.
Splunk search for Cisco ACS data, shows users/device connections to APs
index=firewall sourcetype="cisco:acs" eventtype=cisco_acs_auth_events
| streamstats values(message) as message by message_id
| eval message=mvjoin(message, ",")
| stats values(UserName) as UserName values(User_Name) as User_Name values(Called_Station_ID) as Called_Station_ID by Calling_Station_ID
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment