Getting Data In

Problem with my search (activity log on of 3 users , Active directory)

tinpelayee
Engager

Hello everybody, (Sorry for my english) splunk version 7.0.0
I have two problems on my search

I am searching the activity of log in of three users last month, the problem here is when i want to rename _time as "My Time" , its change to epoch time , and the other problem is i cant find a field of WorkStation_Name where can i find this field? i need this field cause i want to know in what pc has been log in and out.

Here is the search:
index=wineventlog EventCode IN (4624, 4625, 4634) Account_Name IN (randy.flores, johan.benavides, carlos.cruz) Logon_Type=*
| eval Time = strftime(_time, "%Y-%d-%m %H:%M:%S")

|table _time,user, Logon_Type, EventCodeDescription, EventCode , src_ip , Workstation_Name
| rename user as "Nombre de Usuario" , Logon_Type as "Typo de Log On", EventCodeDescription as "Tipo de Evento", src_ip as "Ip" ,

thanks!!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The _time field is always in epoch format, but is displayed as text automatically. If you rename _time you can use the strftime, fieldformat, or convert commands to present the value as a string. Use fieldformat if you need to use 'My Time` a an integer later in your query.

... | eval 'My Time' = strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | fieldformat 'My Time' = (strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime('My Time') as 'My Time'

I believe the workstation field is called "ComputerName". If you run your query in Verbose Mode and look at the events tab you should see the field.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The _time field is always in epoch format, but is displayed as text automatically. If you rename _time you can use the strftime, fieldformat, or convert commands to present the value as a string. Use fieldformat if you need to use 'My Time` a an integer later in your query.

... | eval 'My Time' = strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | fieldformat 'My Time' = (strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime('My Time') as 'My Time'

I believe the workstation field is called "ComputerName". If you run your query in Verbose Mode and look at the events tab you should see the field.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...