By using below Query it's working for to find out the only one windows server but can you please post by using lookup containing all the hosts to Monitor.
index=<your_index> source=WinEventLog* EventCode=41 OR EventCode=1074 OR EventCode=6006 OR EventCode=6008
| stats count by host
| where count > 1
@Vishal2 You are expecting something like this? host_list is the lookup name having host field having pre-populated windows hosts in your org?
index=<your_index> source=WinEventLog* EventCode=41 OR EventCode=1074 OR EventCode=6006 OR EventCode=6008 [| inputlookup host_list | return 1000 host ]
| stats count by host
| where count > 1
@Vishal2 You are expecting something like this? host_list is the lookup name having host field having pre-populated windows hosts in your org?
index=<your_index> source=WinEventLog* EventCode=41 OR EventCode=1074 OR EventCode=6006 OR EventCode=6008 [| inputlookup host_list | return 1000 host ]
| stats count by host
| where count > 1