12-27-2021 12:36 PM
I've noticed that you can search by username in AMP and get the devices that the user has logged into (or possibly generated events on). This is also possible in the API. I am wondering if there is any way to do the reverse. Is there any way to find the most recent user of a machine by hostname (preferably from the API) ?
I know in some cases, you can check the "current user" field in recent events, but I have found a machine where all of the events list "current user" as "none". Even though all events say none, if you search by the username associated with that machine, AMP is still able to find that machine. AMP has to be storing this information somewhere, but I can't find any mention of how to access this data.
Any help would be greatly appreciated.
01-05-2022 09:58 AM - edited 01-05-2022 10:01 AM
Hello @CJ1470,
just some thoughts about the user information included in an endpoint event.
Greetings,
Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide