User Account Audit First and and last logoff events for a 3 month period.

Path Finder

Hi i really could use some help, 

I need to produce a report for the first and last logon events for a couple users over a 3 month period. Does anyone have a nice search query string that i could pinch please. 

I can do basic searches in splunk but anything of any real particulars i struggle with.


any help would be fantastic, i have the Splunk App for windows infrastructure but for some reason the user audit part dashport just says waiting for input, even when i input a user its just stuck there.



