I'm trying to use a where command to filter a search based on 2 values in an event.
So something like where host!=Domain Controller1 and Message!="Bad Username"
But doing it this way is filtering any events that match either host or Message. How can I filter results based on 2 field values?
Try using NOT (host=DomainController1 AND Message="Bad Username")