I need to search my index to determine when a user physically logs on to our network. Event 4624 queries result in all logon events mainly Type 3. I need to report when 'Joe' sat down and logged in and when 'joe' logs out from his workstation Logon Type 2. Thanks
Just do this in verbose mode
index=foo EventID=4624 | head 5
Look at the events, and find the name of the extracted field that contains the Logon Type. Add it to your query.
(On my system, I'd just add EventID=4624 Logon_Type=2
to the query. )