Thank you! If I could ask one more question I'm now wanting to filter that out a bit.
So when looking that up I'm told to do | where user!="SYSTEM" or something like that
EventCode=4624 user!="*$"
| timechart span=1d dc(user) as "Unique Users"
| where user!="SYSTEM"
So that has me think 2 questions. If != is the sign for EXCLUDE then why does this above statement work user!="*$" and second question since it DOES work how can I exclude multiple values?
example: | where user!="SYSTEM","Administrator","Guest", etc?
... View more