cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

dataset = xdr_data
| filter event_type = ENUM.EVENT_LOG and action_evtlog_event_id = 4624
| limit 1

 

Start with xdr_data. This should get you going. Good luck!

Who rated this post