Hello,
I have the below SPL where I am looking to fetch the user accounts that have not logged in for 30 days or more but I am not seeing any results, Can someone please help me with this query if everything is good.
index=windows sourcetype=* EventCode=4624
| stats latest(_time) as lastLogon by Account_Name
| eval days_since_last_logon = round((now() - lastLogon) / 86400, 0)
| where days_since_last_logon > 30
| table Account_Name, days_since_last_logon
Thanks in advance
It looks good to me. Perhaps there are no users who haven't logged in for 30 days. Try changing 30 to 1 as a test.
It looks good to me. Perhaps there are no users who haven't logged in for 30 days. Try changing 30 to 1 as a test.
Yup @richgalloway , it worked now.
I have set it to 1 and tested.
Thanks
If your problem is resolved, then please click the "Accept as Solution" button to help future readers.