<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with hyphen in field values in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529622#M4661</link>
    <description>&lt;P&gt;it's ok I managed to find the problem. i Was not digging far enough into the RAW events and in actual fact the events mentioned Account_name twice with the second value showing as - so Splunk naturally recorded two account names for the events.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Nov 2020 21:05:06 GMT</pubDate>
    <dc:creator>paulw10</dc:creator>
    <dc:date>2020-11-16T21:05:06Z</dc:date>
    <item>
      <title>problem with hyphen in field values</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529603#M4657</link>
      <description>&lt;P&gt;I am trying to create an alert to track failed login events on windows machines&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;index=fa_servers EventCode=4625 OR 533 OR 529&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I have a problem where the account name in the event has a hyphen. Splunk is treating the hyphen as another account name&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Values&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Count&lt;/TD&gt;&lt;TD&gt;%&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://splunkbam.aib.pri:8000/en-US/app/SecOps/search?s=%2FservicesNS%2Fnobody%2FSecOps%2Fsaved%2Fsearches%2FWindows%25202003%253A%2520Last%252024hrs%2520Summary%253A%2520Multiple%2520Failed%2520Logon%2520Attempts&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;q=search%20index%3Dfa_servers%20EventCode%3D4625%20OR%20533%20OR%20529%20Workstation_Name!%3DQualys*%20Account_Name%3D%22-%22&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1605551257.1013873_5BB9F878-880B-4EB4-A828-5F76CC2638E5#" target="_blank" rel="noopener"&gt;-&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;87&lt;/TD&gt;&lt;TD&gt;100%&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="graph-bar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://splunkbam.aib.pri:8000/en-US/app/SecOps/search?s=%2FservicesNS%2Fnobody%2FSecOps%2Fsaved%2Fsearches%2FWindows%25202003%253A%2520Last%252024hrs%2520Summary%253A%2520Multiple%2520Failed%2520Logon%2520Attempts&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;q=search%20index%3Dfa_servers%20EventCode%3D4625%20OR%20533%20OR%20529%20Workstation_Name!%3DQualys*%20Account_Name%3D%22-%22&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1605551257.1013873_5BB9F878-880B-4EB4-A828-5F76CC2638E5#" target="_blank" rel="noopener"&gt;OMGHCLPP-ADS002$&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;46&lt;/TD&gt;&lt;TD&gt;52.874%&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="graph-bar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://splunkbam.aib.pri:8000/en-US/app/SecOps/search?s=%2FservicesNS%2Fnobody%2FSecOps%2Fsaved%2Fsearches%2FWindows%25202003%253A%2520Last%252024hrs%2520Summary%253A%2520Multiple%2520Failed%2520Logon%2520Attempts&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;q=search%20index%3Dfa_servers%20EventCode%3D4625%20OR%20533%20OR%20529%20Workstation_Name!%3DQualys*%20Account_Name%3D%22-%22&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1605551257.1013873_5BB9F878-880B-4EB4-A828-5F76CC2638E5#" target="_blank" rel="noopener"&gt;ALPHCLPP-ADS002$&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;41&lt;/TD&gt;&lt;TD&gt;47.126%&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can see the 87 count is 46+41 so its treating the hyphen as its own value.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been trying to use eval and mvindex to try and just extract the 2 usernames but i am not getting anywhere. can someone explain how i can properly parse these values so it only sees 2 account names&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 19:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529603#M4657</guid>
      <dc:creator>paulw10</dc:creator>
      <dc:date>2020-11-16T19:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: problem with hyphen in field values</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529605#M4658</link>
      <description>&lt;P&gt;Can you share the query you used to get these results and some sample events?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 19:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529605#M4658</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-11-16T19:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: problem with hyphen in field values</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529622#M4661</link>
      <description>&lt;P&gt;it's ok I managed to find the problem. i Was not digging far enough into the RAW events and in actual fact the events mentioned Account_name twice with the second value showing as - so Splunk naturally recorded two account names for the events.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 21:05:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/problem-with-hyphen-in-field-values/m-p/529622#M4661</guid>
      <dc:creator>paulw10</dc:creator>
      <dc:date>2020-11-16T21:05:06Z</dc:date>
    </item>
  </channel>
</rss>

