Hi,
I would like to compare fields in different Eventcodes.
Example:
In Eventcode 4720, I want to get the info for Creator name and Created account, then find the corresponding 4728 event (showing that the created account in 4720, is in a certain OU, like OU=DEV). If the OU is not equal to DEV, trigger alert.
Thanks
Joining may help
eventcode=4720 | join account [search eventcode=4728]
Otherwise you can also try
Hi, i need help.
Account_Name can be found both in eventcodes 4720 and 4728. How do i display the Account_Name information in both eventcodes?
This is what i have:
sourcetype="WinEventLog:Security" (EventCode=4720 AND Account_Name="administrator") OR (EventCode=4728 AND Account_Name="administrator")
| eval AccountCreator=mvindex(Account_Name,0)
| eval AccountCreated=mvindex(Account_Name,1)
| rename Group_Name as "Modified Group"
| table _time, host, AccountCreator, AccountCreated, Modifier, "Modified Group", user
Thx.