index=* success="false" process_name="C:\\Windows\\System32\\svchost.exe"
| stats count as failedAttempts by user
| sort -failedAttempts
index=* success="false" process_name="C:\\Windows\\System32\\svchost.exe"
| timechart count by user
| sort by _time
I tried do both query but I'm stuck...Need any guidance, thank you 🙂
Your fields are not correct. You did not show us sample event data. You did not tell us what "thing' generated the data. You did not tell us what sourcetype it is. You did not tell us what source it is. You did not tell us what ModInput you are using. You did not tell us what TA you are using.