Hello all,
looking to get both the first and last event for each user of the bellow search if anyone can help.
index=wineventlog EventCode=4624 host=machine1* user=4* OR user=5*
I was abler to find a comment someone else made and added this to my base search to resolve my issue thank you
| eval day=strftime(_time,"%d/%m/%Y") | stats earliest(_time) AS earliest latest(_time) AS latest by user host day | eval earliest=strftime(earliest,"%d/%m/%Y %H.%M.%S"), latest=strftime(latest,"%d/%m/%Y %H.%M.%S")
try earliest() and latest() with stats
I was abler to find a comment someone else made and added this to my base search to resolve my issue thank you
| eval day=strftime(_time,"%d/%m/%Y") | stats earliest(_time) AS earliest latest(_time) AS latest by user host day | eval earliest=strftime(earliest,"%d/%m/%Y %H.%M.%S"), latest=strftime(latest,"%d/%m/%Y %H.%M.%S")