Hi
When i'm searching the top users who logged into a host, I'm getting event data along with the user when i'm using pipe.
ex: sourcetype="hostname" "authentication success" | top limit=50 User
Can someone help with this issue?
Hi @jahziah952,
this means that there's an error in field extraction.
the field extraction you're using sometimes doesn't take the correct value, analyze your regex.
I can help you in regex debugging if you can share two kinds of samples. one or two correct events and one or two not correct events.
Ciao.
Giuseppe