Thank you! That was almost exactly what I needed. I just added a filter for retrieving the False field.
Code
index=win sourcetype="WinEventLog:Security" EventCode=4722
| lookup ad_dump.csv SamAccountName AS Target_Account_Account_Name OUTPUT Enabled
| search Enabled=False
... View more