Hey Man, If haven't solved your issue, your search should look like this: index="windows_security" sourcetype="wineventlog:security" (EventCode=4720) | eval creator=mvindex(Account_name,0), Created=mvindex(Account_name,1) | Table Created, Creator Results!
... View more