Hello I am looking to set up a dashboard to monitor or an alert that will help track after hour log ins. Any suggestions
the query will use windows log in events codes.
thank you in advance
date_hour>=17 OR date_hour<=8 | stats count by user
you can start with something basic, assuming after hours are 5:00pm - 8:00am
earliest= @d-7h latest=@d+8h index= sourcetype= EventCode = 4624 | stats count by user