Hello,
I would like to know the aim of this default constraint :
Hi @splunkreal,
user names ending with $ are windows service accounts and usually they aren't relevant in authentication monitoring.
Ciao.
Giuseppe
Hi @splunkreal,
user names ending with $ are windows service accounts and usually they aren't relevant in authentication monitoring.
Ciao.
Giuseppe
As far as I remember, there are two kinds of account that have names ending with $ (in Windows - for other systems it's highly unlikely that there will be an account named this way; but it would be nice to account for that) - Managed Service Accounts (which @gcusello already mentioned) and computer accounts. Both of those account types are authenticated without using interactive authentication modes so they're irrelevant to the events you're looking for in this dataset.