how would i search to see how the amount of license usage per Active Directory (AD) event code?
looking to add it to this search if possible
index=_internal source=*license_usage.log type="Usage" st=MyWindowsLogs | bin _time span=1h | stats sum(b) as b by _time, pool, s, st, h, idx | timechart limit=0 span=1d sum(b) AS volumeB by st fixedrange=false | bin _time span=1d | foreach * [eval <<FIELD>>=round('<<FIELD>>'/1024/1024/1024, 3)] | addtotals
You would have to look at the length of the raw data per event code in the actual index, not the internal metrics.
index=* sourcetype=MyWindowsLogs | stats sum(eval(length(_raw))) as size by EventCode