You probably want to change you search into: index = ad_6mths EventCode="35" OR EventCode="36" OR EventCode="37" OR EventCode="38" source="WinEventLog:System" NOT SourceName="Microsoft-Windows-Time-Service" Followed by a few NOT <useraccounts> See my result below where N column is _time (Date):
... View more