Getting Data In

Problem with my search (activity log on of 3 users , Active directory)

tinpelayee
Engager

Hello everybody, (Sorry for my english) splunk version 7.0.0
I have two problems on my search

I am searching the activity of log in of three users last month, the problem here is when i want to rename _time as "My Time" , its change to epoch time , and the other problem is i cant find a field of WorkStation_Name where can i find this field? i need this field cause i want to know in what pc has been log in and out.

Here is the search:
index=wineventlog EventCode IN (4624, 4625, 4634) Account_Name IN (randy.flores, johan.benavides, carlos.cruz) Logon_Type=*
| eval Time = strftime(_time, "%Y-%d-%m %H:%M:%S")

|table _time,user, Logon_Type, EventCodeDescription, EventCode , src_ip , Workstation_Name
| rename user as "Nombre de Usuario" , Logon_Type as "Typo de Log On", EventCodeDescription as "Tipo de Evento", src_ip as "Ip" ,

thanks!!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The _time field is always in epoch format, but is displayed as text automatically. If you rename _time you can use the strftime, fieldformat, or convert commands to present the value as a string. Use fieldformat if you need to use 'My Time` a an integer later in your query.

... | eval 'My Time' = strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | fieldformat 'My Time' = (strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime('My Time') as 'My Time'

I believe the workstation field is called "ComputerName". If you run your query in Verbose Mode and look at the events tab you should see the field.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The _time field is always in epoch format, but is displayed as text automatically. If you rename _time you can use the strftime, fieldformat, or convert commands to present the value as a string. Use fieldformat if you need to use 'My Time` a an integer later in your query.

... | eval 'My Time' = strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | fieldformat 'My Time' = (strftime( 'My Time', "%Y-%m-%dT%H:%M:%S")

... | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime('My Time') as 'My Time'

I believe the workstation field is called "ComputerName". If you run your query in Verbose Mode and look at the events tab you should see the field.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...