Hello everybody, (Sorry for my english) splunk version 7.0.0
I have two problems on my search
I am searching the activity of log in of three users last month, the problem here is when i want to rename _time as "My Time" , its change to epoch time , and the other problem is i cant find a field of WorkStation_Name where can i find this field? i need this field cause i want to know in what pc has been log in and out.
Here is the search:
index=wineventlog EventCode IN (4624, 4625, 4634) Account_Name IN (randy.flores, johan.benavides, carlos.cruz) Logon_Type=*
| eval Time = strftime(_time, "%Y-%d-%m %H:%M:%S")
|table _time,user, Logon_Type, EventCodeDescription, EventCode , src_ip , Workstation_Name
| rename user as "Nombre de Usuario" , Logon_Type as "Typo de Log On", EventCodeDescription as "Tipo de Evento", src_ip as "Ip" ,
thanks!!
The _time
field is always in epoch format, but is displayed as text automatically. If you rename _time
you can use the strftime
, fieldformat
, or convert
commands to present the value as a string. Use fieldformat
if you need to use 'My Time` a an integer later in your query.
... | eval 'My Time' = strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")
... | fieldformat 'My Time' = (strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")
... | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime('My Time') as 'My Time'
I believe the workstation field is called "ComputerName". If you run your query in Verbose Mode and look at the events tab you should see the field.
The _time
field is always in epoch format, but is displayed as text automatically. If you rename _time
you can use the strftime
, fieldformat
, or convert
commands to present the value as a string. Use fieldformat
if you need to use 'My Time` a an integer later in your query.
... | eval 'My Time' = strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")
... | fieldformat 'My Time' = (strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")
... | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime('My Time') as 'My Time'
I believe the workstation field is called "ComputerName". If you run your query in Verbose Mode and look at the events tab you should see the field.