Hello,
I’m a newbie trying to wrap my head around writing these queries.
What I would like to do is run a report that returns time of an event, account name and machine name of a specific windows event id during the last 24 hours.
For example, security event log Event ID 4625 on Tues, May 2 2018 at 10:30, on computer wsk123 for user JDOE
An added bonus if I could specify a specific date I want to return results on , that would be awesome.
What I have so far is:
(time generated of it) of records whose (event id of it = 4625 AND now - time generated of it < 1*day AND description of it contains “An account failed to log on.”) of security event log
Which will list all the event times in the last 24 hours.
How can I add to the query for additional like username and machine name from the Event description “Subject: Account Name:” and “Network Information: Workstation Name:”
Ideal output would be:
Tue, 01 May 2018 23:06:05 -0700, JDOE, WSK123
Thanks in advanced for any help!