How can I make a table for multiple Windows Events ? This search gives me good results for one Event Code, but I have multiple Event IDs. Trying to do some tuning.
index=wineventlog source=WinEventLog:security EventCode=4624
| fields _raw
| eval esize=len(_raw)
| stats count as count avg(esize) as avg
| eval bytes=count*avg
| eval kb=bytes/1024
| eval mb=round(kb/1024,2)
| stats values(kb) as KB, values(mb) AS MB
Like this:
index=wineventlog source=WinEventLog:security
| fields _raw
| eval esize=len(_raw)
| stats count AS count avg(esize) AS avg
| eval bytes=count*avg
| eval kb=bytes/1024
| eval mb=round(kb/1024,2)
| stats values(kb) AS KB, values(mb) AS MB BY EventCode
Also be aware that convert
and has some things to do the bytes->whatever things.
How about splitting by EventCode:
index=wineventlog source=WinEventLog:security
| fields _raw
| eval esize=len(_raw)
| stats count as count avg(esize) as avg by EventCode
| eval bytes=count*avg
| eval kb=bytes/1024
| eval mb=round(kb/1024,2)
| stats values(kb) as KB, values(mb) AS MB by EventCode