Hello, thank you for getting back to me,
Thats working as follows;
Machine Backedup Event Code
DCAOVSG001 22
DCAOVSG002 21
DCAOVSG003 21
Which is the basis of what i am after, i just need to change the 21 to pass, 22 to fail message and then add a date.
So what ive done is added
| eval Outcome=if(EventCode=21,"Success","Fail")
| fields - EventCode
| convert ctime("Date")|rename Machine_BackedUp as "Computer Name"
onto the bottom of your search so that it looks like this:
index=windows_health-servers sourcetype="WinEventLog:Application" (EventCode=21 OR EventCode=22)
| where match(Machine_BackedUp,"DC(A|P)OV\w{2}\d{3}")
| stats latest(EventCode) as EventCode by Machine_BackedUp
| eval Outcome=if(EventCode=21,"Success","Fail")
| fields - EventCode
| convert ctime("Date")|rename Machine_BackedUp as "Computer Name"
i need to sort the time out by you my good sir are both a scholar and a gent. Thank you ever so much.
... View more