- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How do report for Windows logon and logoff per user day-by-day
Nraj87
Explorer
08-08-2024
08:43 AM
Is it possible to get each day first login event( EventCode=4634) as "logon" and Last event of (EventCode=4634) as Logoff and calculate total duration .
index=win sourcetype="wineventlog" EventCode=4624 OR EventCode=4634 NOT
| eval action=case((EventCode=4624), "LOGON", (EventCode=4634), "LOGOFF", true(), "ERROR")
| bin _time span=1d
| stats count by _time action user
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
08-08-2024
09:29 AM
Try something like this
index=win sourcetype="wineventlog" EventCode=4624 OR EventCode=4634
| bin _time as day span=1d
| stats count min(eval(if(EventCode=4624,_time,null()))) as first_logon max(eval(if(EventCode=4634,_time,null)))) as last_logout by day user
