I need to check the logs against Workstation XYZ to ensure no one else besides JDOE has logged into it from 9/15/20 00:00:00.000 until 9/22/20. 23:59;59.999 (7-days). What would be the best SPL to run to check this?
Hi @itsmevic,
if you're speking of windows logs, you should try something like this:
index=wineventlog EventCode=4624 workstation=XYZ user!=JDOE
please check if the fields workstation and user are written in your logs in this way, because I have an italian Windows and I have different fieldnames, but anyway you can see the approach.
Ciao.
Giuseppe
Thank you both!
Hi @itsmevic,
if you're speking of windows logs, you should try something like this:
index=wineventlog EventCode=4624 workstation=XYZ user!=JDOE
please check if the fields workstation and user are written in your logs in this way, because I have an italian Windows and I have different fieldnames, but anyway you can see the approach.
Ciao.
Giuseppe
Search for login events where workstation = XYZ where user != JDOE