Newbie here, so please be kind!
Not sure if this is even possible, but I need to find out if a user has never logged in to a host. So far I have this:
sourcetype="WMI:UserAccounts" user="Bob" | stats count by host
That gives me the hosts Bob has logged in to, but not the hosts that Bob has not logged in to (which is what I need).
Can this be done?
Thinking about this a bit more, you should be able to do what the OP needs without a subsearch:
sourcetype="WMI:UserAccounts" | stats count(eval(User="Bob")) as bobcount by host | where bobcount=0