Dashboards & Visualizations
Highlighted

Dashboards - Show line charts by users, how many failed log in and time

Builder

I wanna this:
http://prntscr.com/h9xqgm

This is my search:
eventtype=msad-failed-user-logons (host="*")|fields time,signature,srcip,srchost,srcnthost,srcntdomain,user,LogonType |ip-to-host|fix-localhost|stats count by user,srcnthost,srcip|sort -count|rename user as "Username" srcnthost as "Workstation",srcip as "IP Address" | head 6

Results of search:
http://prntscr.com/h9xjt8

I need include to line charts - users, have my times failed log in and time. How should I change this search?

0 Karma
Highlighted

Re: Dashboards - Show line charts by users, how many failed log in and time

Legend

@test_qweqwe, you want to plot a timechart then you need _time as one of the fields. Your stats query is removing _time field. Also if you just need count by user over _time, you do not need to worry about other fields. Try the following search. I am expecting your eventtype msad-failed-user-logons gives only failed user logon events.

eventtype=msad-failed-user-logons (host="*")
| timechart count by user



| eval message="Happy Splunking!!!"


View solution in original post