Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SELECT
- timegenerated,
- EXTRACT_TOKEN(Strings,0,`|`) AS USER,
- EXTRACT_TOKEN(Strings,6,`|`) AS SOURCE
- INTO %eventtype%.csv
- FROM %input%
- WHERE EventID IN (528; 540)
- AND CASE EXTRACT_TOKEN(Strings,3,`|`)
- WHEN '2' THEN 'local'
- WHEN '3' THEN 'network'
- WHEN '5' THEN 'administrative'
- WHEN '7' THEN 'unloc'
- END = '%eventtype%'
- --failed
- SELECT
- timegenerated,
- EXTRACT_TOKEN(Strings,0,`|`) AS USER,
- EXTRACT_TOKEN(Strings,6,`|`) AS SOURCE
- INTO %eventtype%.csv
- FROM %input%
- WHERE EventID BETWEEN 529 AND 537
- AND CASE EXTRACT_TOKEN(Strings,2,`|`)
- WHEN '2' THEN 'local'
- WHEN '3' THEN 'network'
- WHEN '5' THEN 'administrative'
- WHEN '7' THEN 'unloc'
- END = '%eventtype%'
- --user
- SELECT
- *
- --, EXTRACT_TOKEN(Strings,0,`|`) AS user,
- --EXTRACT_TOKEN(Strings,6,`|`) AS source
- INTO users.csv
- FROM %input%
- WHERE EventID IN (4720; 4722; 4725; 4726)
- LogParser -i:EVT "SELECT COUNT(*) AS Times, EventType INTO Chart.gif FROM test.evt GROUP BY EventType" -chartType:PieExploded3D -chartTitle:"HAHAHA"
- LogParser -i:EVT "SELECT TimeGenerated, COUNT(*) AS Times INTO Chart2.gif FROM test.evt GROUP BY TimeGenerated" -o:chart -chartType:Column3D -chartTitle:"By times"
- LogParser -i:EVT "SELECT TimeGenerated, COUNT(*) AS Times INTO Chart3.gif FROM test.evt WHERE TimeGenerated >= TIMESTAMP('2017-02-01', 'yyyy-MM-dd') GROUP BY TimeGenerated" -o:chart -chartType:Column3D -chartTitle:"By times"
- Фильтр по времени
- LogParser -i:EVT "SELECT TimeGenerated, COUNT(*) AS Times INTO Chart3.gif FROM test.evt WHERE TimeGenerated >= TIMESTAMP('2017-02-01', 'yyyy-MM-dd') AND TimeGenerated < TIMESTAMP('2017-03-01','yyyy-MM-dd') GROUP BY TimeGenerated" -o:chart -chartType:Column3D -chartTitle:"By times"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement