Splunk Search

Exacting Account_Name from security logs

Path Finder

Your rex command does nothing at all so we can remove it. You also are not using Region so it can go. The dedup command is more efficient that stats.

Try this:

index=security  sourcetype="WinEventLog:*" object="WinEventLog:Security"
| eval SID=Upper(SID) | dedup SID host
| table host SID
| lookup Phonebook_Lookup SID Output First_Name Last_Name
| sort 0 host
0 Karma


If you're only concerned about windows security logs, can you make the sourcetype WinEventLog:Security?

What is the goal of the rex command you have there? Account_Name is an extracted field.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!