So I currently have Windows event log (security) files and am attempting to compare two strings that are pulled out via the rex command (lets call them "oldlogin" and "newlogin")
Values of each variable are as follows:
oldlogin = ad.user.name
newlogin = user.name
What I am trying to do is to compare oldlogin and newlogin, and if they are both the same (minus the "ad.), then don't return them.
Unfortunately, I am rather new to Splunk and am not familiar with how to do this, so I will try to provide as much data as possible upon request.
... View more