Hello everybody, (Sorry for my english) splunk version 7.0.0
I have two problems on my search
I am searching the activity of log in of three users last month, the problem here is when i want to rename time as "My Time" , its change to epoch time , and the other problem is i cant find a field of WorkStationName where can i find this field? i need this field cause i want to know in what pc has been log in and out.
Here is the search:
index=wineventlog EventCode IN (4624, 4625, 4634) AccountName IN (randy.flores, johan.benavides, carlos.cruz) LogonType=*
| eval Time = strftime(_time, "%Y-%d-%m %H:%M:%S")
|table time,user, LogonType, EventCodeDescription, EventCode , srcip , WorkstationName
| rename user as "Nombre de Usuario" , LogonType as "Typo de Log On", EventCodeDescription as "Tipo de Evento", srcip as "Ip" ,
The _time field is always in epoch format, but is displayed as text automatically. If you rename _time you can use the strftime, fieldformat, or convert commands to present the value as a string. Use fieldformat if you need to use 'My Time` a an integer later in your query.