The previous Query was counting all events displayed. I modified this further and now I can get a failure count by ip. index=windows EventCode=4625 ip!="private ip range to exclude" ip!="127.0.0.1" ip!="::1" ip!="-" | stats count as failures by ip, EventCode, ComputerName,| table EventCode ip failures ComputerName | sort failures | reverse In addition you can easily add hostnames you wish to exclude with the line below by adding this before the | stats ComputerName!="hostname you'd like to exclude that's noisy or you're aware of"
... View more