Hi i really could use some help,
I need to produce a report for the first and last logon events for a couple users over a 3 month period. Does anyone have a nice search query string that i could pinch please.
I can do basic searches in splunk but anything of any real particulars i struggle with.
any help would be fantastic, i have the Splunk App for windows infrastructure but for some reason the user audit part dashport just says waiting for input, even when i input a user its just stuck there.
Regards