Splunk Search

Displaying unwanted user names on the output

brpsingara
Explorer

Below is my code and I want to display only "Druv" Failed logins. But, I see the user name 'None' , 'Karla' and other few names.

How avoid the unwanted users in the output

index=wineventlog source="WinEventLog:Security" sourcetype=WinEventLog:Security EventCode=4625 where Account_Name=Druv
| stats count by _time, Workstation_Name,Account_Name,dest, dest_nt_domain, product, app, action, EventCode, EventCodeDescription, Failure_Reason, name 
| sort  _time
| where Account_Name!="-"

Thanks in advance

Tags (1)
0 Karma

to4kawa
Ultra Champion
index=wineventlog source="WinEventLog:Security" sourcetype=WinEventLog:Security EventCode=4625 Account_Name="Druv"
 | stats count by _time, Workstation_Name,Account_Name,dest, dest_nt_domain, product, app, action, EventCode, EventCodeDescription, Failure_Reason, name 
 | sort  _time

I exclude where. typo?

0 Karma

brpsingara
Explorer

thank you

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...