Hello,
I'd like my search to return 30 min interval searches between 9/24/2020 20:00 and the current date; what's the best way to do this? I'm trying to investigate what is causing lockouts every six hours on Account_Name="johndoe" Suggestions are greatly welcomed.
index=* source=win* Account_Name=johndoe EventCode=4740
The simple answer is
| timechart span=30 count
but I am not sure if that's what you're looking for, as I don't really understand what would help you do the investigations.