It returned the field as Workstation_Name, but I've tried:
EventIdentifier=4624 | ...
every single one of these returns "Error in 'anomalousvalue' command: found no qualifying results. Please verify that the field names are correct"
Well that doesn't work so I guess it isn't a 'field'. This is annoying and confusing.
The event data has a section like this...
Workstation Name: TestClientPc
Source Network Address: 192.168.1.247
Source Port: 52404
So what the heck do I do here? Is this something I have to use eval() for?
EventIdentifier is a field so some fields are being created. What do you get from this:
EventIdentifier=4624 | stats first(*)
This will show you what fields do exist. Perhaps this field is being extracted as
Name instead of