SOLVED

log search showing logged on users

%3CLINGO-SUB%20id%3D%22lingo-sub-130835%22%20slang%3D%22en-US%22%3Elog%20search%20showing%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-130835%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI'm%20not%20sure%20if%20this%20is%20the%20right%20place%20to%20ask%2C%20but%20here%20goes.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20been%20asked%20to%20make%20a%20dashboard%20showing%20the%20count%20of%20users%20currently%20logged%20in%20to%20our%20local%20ad.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20the%20data%20in%20oms%2C%20and%20i%20have%20made%20this%20query%20so%20fare%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESecurityEvent%3C%2FP%3E%0A%3CP%3E%7C%20where%20EventID%20%3D%3D%204624%3CBR%20%2F%3E%7C%20where%20(%20LogonTypeName%20%3D%3D%20%223%20-%20Network%22%20)%3CBR%20%2F%3E%7C%20where%20(%20Computer%20%3D%3D%20%22ad%20server%22%20)%20%3CBR%20%2F%3E%7C%20where%20AccountType%20%3D%3D%20%22User%22%3CBR%20%2F%3E%7C%20summarize%20count()%20by%20TargetAccount%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBut%20i'm%20kind%20of%20stuck%20here.%3C%2FP%3E%0A%3CP%3EI%20can't%20get%20it%20to%20show%20a%20number%2C%20i%20have%20tried%20different%20methods%2C%20but%20not%20with%20the%20result%20i%20was%20hoping%20for.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20for%20some%20input%20or%20pointers%20to%20what%20i%20can%20do.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20regards%3C%2FP%3E%0A%3CP%3EJan%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-130835%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-131481%22%20slang%3D%22en-US%22%3ERe%3A%20log%20search%20showing%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-131481%22%20slang%3D%22en-US%22%3E%3CP%3EThat%20help%2C%20thank%20you%2C%20i%20completly%20missed%20the%20dcount%20parameter.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENow%20i%20just%20have%20to%20get%20the%20joins%20to%20work.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERagards%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EJan%20Dam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-130873%22%20slang%3D%22en-US%22%3ERe%3A%20log%20search%20showing%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-130873%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Jan%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIs%20this%20what%20you%20are%20looking%20for%3A%3C%2FP%3E%0A%3CP%3ESecurityEvent%3C%2FP%3E%0A%3CP%3E%7C%20where%20EventID%20%3D%3D%204624%3CBR%20%2F%3E%7C%20where%20(%20LogonTypeName%20%3D%3D%20%223%20-%20Network%22%20)%3CBR%20%2F%3E%7C%20where%20(%20Computer%20%3D%3D%20%22ad%20server%22%20)%20%3CBR%20%2F%3E%7C%20where%20AccountType%20%3D%3D%20%22User%22%3CBR%20%2F%3E%7C%20summarize%20dcount(TargetAccount)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIt%20would%20show%20you%20total%20number%20of%20users%20that%20logged%20on%20to%20the%20server%20but%20not%20the%20number%20of%20users%20that%20are%20currently%20logged%20on.%3C%2FP%3E%0A%3CP%3ETo%20do%20this%2C%20you%20need%20to%20left%20Join%20the%20list%20of%20users%20on%20the%204624%20records%20with%20the%20list%20of%20users%20that%20have%204634%20or%204647%20records.%20Those%20that%20doesn't%20have%20a%20match%20are%20still%20logged%20on.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20this%20helps%2C%3C%2FP%3E%0A%3CP%3EMeir%20%3A%26gt%3B%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi all.

 

I'm not sure if this is the right place to ask, but here goes.

 

I have been asked to make a dashboard showing the count of users currently logged in to our local ad.

 

I have the data in oms, and i have made this query so fare:

 

SecurityEvent

| where EventID == 4624
| where ( LogonTypeName == "3 - Network" )
| where ( Computer == "ad server" )
| where AccountType == "User"
| summarize count() by TargetAccount

 

But i'm kind of stuck here.

I can't get it to show a number, i have tried different methods, but not with the result i was hoping for.

 

Hope for some input or pointers to what i can do.

 

Best regards

Jan

 

2 Replies
best response confirmed by Jan Løbner Dam (New Contributor)
Solution

Hi Jan,

 

 

Is this what you are looking for:

SecurityEvent

| where EventID == 4624
| where ( LogonTypeName == "3 - Network" )
| where ( Computer == "ad server" )
| where AccountType == "User"
| summarize dcount(TargetAccount)

 

?

 

It would show you total number of users that logged on to the server but not the number of users that are currently logged on.

To do this, you need to left Join the list of users on the 4624 records with the list of users that have 4634 or 4647 records. Those that doesn't have a match are still logged on.

 

Hope this helps,

Meir :>

That help, thank you, i completly missed the dcount parameter.

 

Now i just have to get the joins to work.

 

Ragards

 

Jan Dam