Query doesnt bring up anything.
Try to pull RDP connections in my environment:
event_simpleName=UserLogon LogonType_decimal=10
| stats values(UserName) dc(UserName) AS "User Count" count(UserName) AS "Logon Count" by aid, ComputerName
| sort - "Logon Count"
First, illustrate your raw data. Are "aid" and "ComputerName" available at search time, AND are they present in (at least some of) the same events? For example, what does this give you?
event_simpleName=UserLogon LogonType_decimal=10
| table aid, ComputerName
Also, the search appears to be about user name. How does this relate to "pulling RDP connections" in the title?
Thanks for the answer
First, illustrate your raw data. Are "aid" and "ComputerName" available at search time, AND are they present in (at least some of) the same events? For example, what does this give you?
event_simpleName=UserLogon LogonType_decimal=10
| table aid, ComputerName
Also, the search appears to be about user name. How does this relate to "pulling RDP connections" in the title?