Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SELECT timegenerated, EXTRACT_TOKEN(Strings,1,'|') AS rec, EXTRACT_TOKEN(Strings,0,'|') AS user, SID, CASE EXTRACT_TOKEN(Strings,3,'|')
- WHEN '2' THEN 'local'
- WHEN '3' THEN 'network'
- WHEN '5' THEN 'administrative'
- WHEN '7' THEN 'unlock' END AS type, EventID,
- CASE EXTRACT_TOKEN(Strings,6,'|')
- WHEN rec THEN ''
- ELSE EXTRACT_TOKEN(Strings,6,'|') END
- INTO Report\%param%.csv
- FROM Events\secur.evt WHERE EventID IN (528;540)
- AND
- type = '%param%'
- ORDER BY timegenerated DESC
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement