I've noticed that you can search by username in AMP and get the devices that the user has logged into (or possibly generated events on). This is also possible in the API. I am wondering if there is any way to do the reverse. Is there any way to find the most recent user of a machine by hostname (preferably from the API) ?
I know in some cases, you can check the "current user" field in recent events, but I have found a machine where all of the events list "current user" as "none". Even though all events say none, if you search by the username associated with that machine, AMP is still able to find that machine. AMP has to be storing this information somewhere, but I can't find any mention of how to access this data.
Any help would be greatly appreciated.