Okay... this must be a stumper... how about this... this report (Windows Login Failure Report) list incorrect Window logins with time and date... Is there a way to modify this report to list incorrect logins from 5pm to 8am?
Select Top 1000000 tblNtlog.TimeGenerated,
tblAssets.AssetID,
tblAssets.AssetUnique,
tblAssets.Domain,
tblNtlog.Eventcode,
tblNtlogFile.Logfile,
SubString(tblNtlogMessage.Message, CharIndex('Account Name:',
tblNtlogMessage.Message, CharIndex('Account Name:', tblNtlogMessage.Message,
1) + 1) + 14, CharIndex('Account Domain:', tblNtlogMessage.Message,
CharIndex('Account Domain:', tblNtlogMessage.Message, 1) + 1) -
CharIndex('Account Name:', tblNtlogMessage.Message, CharIndex('Account Name:',
tblNtlogMessage.Message, 1) + 1) - 14) As [User Name],
SubString(tblNtlogMessage.Message, CharIndex('Failure Reason:',
tblNtlogMessage.Message, 1) + 16, CharIndex('Status:',
tblNtlogMessage.Message, 1) - CharIndex('Failure Reason:',
tblNtlogMessage.Message, 1) - 16) As Reason
From tblNtlog
Inner Join tblNtlogFile On tblNtlogFile.LogfileID = tblNtlog.LogfileID
Inner Join tblNtlogMessage On tblNtlogMessage.MessageID = tblNtlog.MessageID
Inner Join tblNtlogSource On tblNtlogSource.SourcenameID =
tblNtlog.SourcenameID
Inner Join tblNtlogUser On tblNtlogUser.LoguserID = tblNtlog.LoguserID
Inner Join tblAssets On tblAssets.AssetID = tblNtlog.AssetID
Where (tblNtlog.Eventcode = 4723 Or tblNtlog.Eventcode = 4625) And
SubString(tblNtlogMessage.Message, CharIndex('Failure Reason:',
tblNtlogMessage.Message, 1) + 16, CharIndex('Status:',
tblNtlogMessage.Message, 1) - CharIndex('Failure Reason:',
tblNtlogMessage.Message, 1) - 16) Not Like '%ERROR%' And
CharIndex('Account Name:', tblNtlogMessage.Message, CharIndex('Account Name:',
tblNtlogMessage.Message, 1) + 1) > 1 And CharIndex('Account Domain:',
tblNtlogMessage.Message, CharIndex('Account Domain:', tblNtlogMessage.Message,
1) + 1) > 1 And CharIndex('Failure Reason:', tblNtlogMessage.Message, 1) > 1
And CharIndex('Status:', tblNtlogMessage.Message, 1) > 1
Order By tblNtlog.TimeGenerated Desc