Hi @gcusello Thank you I have change the query little bit as I was getting no successful attempt also in the table.. But little bit concern with the time span I gave very minimal time to test the query but it is not showing zero events For example index=sdp_siem_win source=WinEventLog:Security (EventCode=4625 OR EventCode=4624) | eval username=mvindex(Account_Name, 1) | stats count(eval(EventCode="4625")) AS Failed_count count(eval(EventCode="4624")) AS Success_count first(eval(if(EventCode="4624",strftime(_time,"%Y-%m-%d %H:%M:%S")." "."Success",""))) AS Success values(eval(if(EventCode="4625",strftime(_time,"%Y-%m-%d %H:%M:%S")." "."Failed",""))) AS Failed earliest(_time) AS earliest latest(_time) AS latest by host username | eval alert=if(Failed_count>5, "more_fails", "no_more_fails") | where alert="more_fails" AND Success_count>0 | table username host Failed Failed_count Success alert | search Success!="" The above query showing the result but if I time time function then it is showing 0 result index=sdp_siem_win source=WinEventLog:Security (EventCode=4625 OR EventCode=4624) | eval username=mvindex(Account_Name, 1) | bin span=2m _time | stats count(eval(EventCode="4625")) AS Failed_count count(eval(EventCode="4624")) AS Success_count first(eval(if(EventCode="4624",strftime(_time,"%Y-%m-%d %H:%M:%S")." "."Success",""))) AS Success values(eval(if(EventCode="4625",strftime(_time,"%Y-%m-%d %H:%M:%S")." "."Failed",""))) AS Failed earliest(_time) AS earliest latest(_time) AS latest by host username | eval alert=if(Failed_count>5, "more_fails", "no_more_fails") | where alert="more_fails" AND Success_count>0 AND latest-earliest<120 | table username host Failed Failed_count Success alert | search Success!="" Can you please guide me where I get wrong Thanks
... View more