I'm trying to query instances where Security_ID != {Domain Name}\Account_Name in the security event logs per Microsoft's guidance, but I can't concatenate the Domain Name and Account Name in the query.
E.g. CONTOSO\bob != bob
All help is appreciated!!
... View more