I'm surprised, I honestly thought I provided enough details. I really don't see how this will help but here it is: index=os sourcetype="xmlwineventlog" ``` extract and normalize the Domain name ``` | rex field=source "/aws/directoryservice/(?<ds_name>.+):" | eval Domain = if( lower( substr(ds_name,0,2))="zo", lower( substr(ds_name, 0, 8)), lower( substr(ds_name, 14, len(ds_name) - 12))) ``` extract and normalize the Domain Controller hostname ``` | rex field=Computer "(?<DC_extract>.+).z" | eval DC_hostname = if( isnull( DC_extract ), upper(Computer), upper( DC_extract ) ) ``` count how many messages from each DC ``` | stats count by Domain, DC_hostname ``` now count how many DCs per-domain | stats count by Domain `` finally, notify of any domains with more than 2 DCs ``` | where count>2
... View more