Here is my search:
source="WinEventLog:Security" EventCode="4723" OR EventCode="529" | eval UserName=coalesce(User_Name,Account_Name) | stats count by UserName |sort -count |head 10
The problem is that the field "Account_Name"
appears more than once in the record, so the count is effectively doubled. How can I get the correct count of the records instead of counting the field name twice?
i found a solution. i am doing a distinct count on the record number, and that returns the correct number of records
host="rh-dc*" EventCode=4723
| stats dc(RecordNumber) by Account_Name
| sort -count