I wanna this:
http://prntscr.com/h9xqgm
This is my search:
eventtype=msad-failed-user-logons (host="*")|fields _time,signature,src_ip,src_host,src_nt_host,src_nt_domain,user,Logon_Type |ip-to-host
|fix-localhost
|stats count by user,src_nt_host,src_ip|sort -count|rename user as "Username" src_nt_host as "Workstation",src_ip as "IP Address" | head 6
Results of search:
http://prntscr.com/h9xjt8
I need include to line charts - users, have my times failed log in and time. How should I change this search?
@test_qweqwe, you want to plot a timechart then you need _time as one of the fields. Your stats query is removing _time field. Also if you just need count by user over _time, you do not need to worry about other fields. Try the following search. I am expecting your eventtype msad-failed-user-logons
gives only failed user logon events.
eventtype=msad-failed-user-logons (host="*")
| timechart count by user
@test_qweqwe, you want to plot a timechart then you need _time as one of the fields. Your stats query is removing _time field. Also if you just need count by user over _time, you do not need to worry about other fields. Try the following search. I am expecting your eventtype msad-failed-user-logons
gives only failed user logon events.
eventtype=msad-failed-user-logons (host="*")
| timechart count by user