Hi,
I need to pull the description and office fields in active directory in my SPL query. What would be the best syntax to use. What I am doing is simply a basic string search for "TOR" and would like the results to list also the user's description and office field values within AD.
Current Search:
index=* sourcetype=* "TOR"
|stats count by user
|ldapfilter search="(&(objectclass=user)(!(objectClass=computer))(samAccountName=$samAccountName$))" attrs="description, physicalDeliveryOfficeName"
|sort -count
I don't have experience with this command, but the examples in the documentation show outputting to the "table" command. You might want to try adding:
| table user,description,physicalDeliveryOfficeName,count
ahead of the sort