When running the |snoweventstream command it returns the columns: "Time of the event", "_time","State","Source","Event Link","Node","Severity","Resource","Type" and "Sys Id". Is there a way to add more columns to the results returned?
For example, in my search, I am looking for PCName. What I would like to do is, when I run the |snoweventstream command, have it return these results.
"Time of the event", "_time","State","Source","Event Link","Node","Severity","Resource","Type","Sys Id" and "PCName"
Is that possible?
... View more