I was hoping to modify the query to give me a nice visualization of RDP Activity focusing only on the 1149 Events.
index="xxxx" LogName="Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational" EventCode=1149| eval time=strftime(_time,"%Y-%m-%dT%H:%M:%SZ") | rex field=_raw ".*User:\s+(?<User>.*)\r\n" | rex field=_raw ".*Domain:\s+(?<Domain>.*)\r\n" | rex field=_raw ".*Network\sAddress:\s+(?<IP>.*)" | table host, time, User, Domain, IP
This gives me a very pretty tabular format of RDP attempts (not confirmed successful logins at times, but will do)
How could I possibly edit the query in Github to cater to my needs?
Apart from this, is there a way we can visualize (4624?) or Lateral Movement in the form of a picture/timeline using Splunk?