Getting Data In
Highlighted

What is a search to find a users logging into windows?

Splunk Employee
Splunk Employee

index=main sourcetype="WinEventLog:Security" EventCode=4624 |stats count by Account_Name

0 Karma
Highlighted

Re: What is a search to find a users logging into windows?

Splunk Employee
Splunk Employee
 index=main sourcetype="WinEventLog:Security" EventCode=4624 |stats count by Account_Name

View solution in original post

0 Karma