Is there a way to rename EventCodes xxxx field to "description" in timechart? Here is a sample search:
Account_Name=* (EventCode=4800 OR EventCode=4801 OR EventCode=4768) index=blah sourcetype="WinEventLog:Security" source="WinEventLog:Security" | timechart count by EventCode
Thanks!
↧