1) I am using below code to getting all machines list ,
| metadata type=host index=* | stats count by host
is possible to get IP address also ?
2) Here also I need IP address required,
index=windeventlog sourcetype=winEventLog:Security EventCode=4625
| stats count by Account_Name, EventCode, Workstation_Name
| cort by - count
please suggest.
Thanks in advance.
both log doesn't have ip address. you can't.