I know this has been answered long ago, but I'm surprised that no one has mentioned eval and mvindex yet. With a multi-value field, you can use mvindex to target the first, second (or third or fourth, etc.) value of a field with the same name.
...
| eval subject_account=mvindex(Account_Name, 0)
| eval target_account=mvindex(Account_Name, 1)
| where target_account = "some_account"
Some events also have an empty target account, in which case you can write an if statement into your eval. See this answer for an example.
http://splunk-base.splunk.com/answers/48096/account_name-field-listing-in-events-4624-4768-and-4769-windows-2008
For cases like Account_Name, I find the mvindex to be much easier to use than regular expressions.
... View more