Hello,
my current search is
index=winsec source=WinEventLog:Security EventCode=6272
| eval date_hour = strftime(_time, "%H")
| where date_hour >= 19 OR date_hour <=06
| timechart count(src_user)
This provides me with a graph of logins made after hours. I want to expand the acceptable items to include the entire days of saturday/sunday as well. When I attempt to add this, i get "no results" what would be the best way to include that?
Extract and test for the day of the week similar to how date_hour was done.
index=winsec source=WinEventLog:Security EventCode=6272
| eval date_hour = strftime(_time, "%H"), date_wday = strftime(_time, "%A")
| where date_hour >= 19 OR date_hour <=06 OR date_wday = "Saturday" OR date_wday = "Sunday"
| timechart count(src_user)
Extract and test for the day of the week similar to how date_hour was done.
index=winsec source=WinEventLog:Security EventCode=6272
| eval date_hour = strftime(_time, "%H"), date_wday = strftime(_time, "%A")
| where date_hour >= 19 OR date_hour <=06 OR date_wday = "Saturday" OR date_wday = "Sunday"
| timechart count(src_user)
I think this would work perfectly, but the system does not appear to have date_wday enabled. Using this term always provides me with " no results"
The date_wday is being created with the eval command on the second line...
I'll break it down for you.
| eval date_hour = strftime(_time, "%H")
| eval date_wday = strftime(_time, "%A")
You're right! my mistake, I didn't read the entire query.
Thanks for pointing out my mistake!