Can someone please help with a search I'm trying to create. My end goal is to capture which user account logged into the server and have a time associated with their login.
My search so far is below. This only gives me the count of how many times the users logged in for the past "x" days.
index="wineventlog" host="Redacted" source="XmlWinEventLog:Security" | stats count by SubjectUserSid