Trying to build a data table with split rows from multiple windows event ID's.
Event ID 4648 - Network Logon with exp credentials
Grabbing the following-
Computer_Name TargetUsername SubjectUsername TargetServer
works great. But I want to have a table with several different event ID's that may or may not have that field
Event ID 4624 - NTLM Authentication
Computer_Name TargetUsername SubjectUsername ... but not TargetServer
so you can't see both event ID's on the same data table.
Is there a way to still show the data table even if the event ID's don't have the same exact fields? I.E. if the event ID isn't present just show the field as blank?
So I could show both 4648 and 4624 in the same table on the same visualization with similar but not perfect matching fields?