Exacting Account_Name from security logs

Your rex command does nothing at all so we can remove it. You also are not using Region so it can go. The dedup command is more efficient that stats.

Try this:

index=security  sourcetype="WinEventLog:*" object="WinEventLog:Security"
| eval SID=Upper(SID) | dedup SID host
| table host SID
| lookup Phonebook_Lookup SID Output First_Name Last_Name
| sort 0 host
If you're only concerned about windows security logs, can you make the sourcetype WinEventLog:Security?

What is the goal of the rex command you have there? Account_Name is an extracted field.

