Your rex
command does nothing at all so we can remove it. You also are not using Region
so it can go. The dedup
command is more efficient that stats
.
Try this:
index=security sourcetype="WinEventLog:*" object="WinEventLog:Security"
| eval SID=Upper(SID) | dedup SID host
| table host SID
| lookup Phonebook_Lookup SID Output First_Name Last_Name
| sort 0 host
If you're only concerned about windows security logs, can you make the sourcetype WinEventLog:Security?
What is the goal of the rex command you have there? Account_Name is an extracted field.