| datamodel "Change_Analysis" "Account_Management" search | where 'All_Changes.tag'="delete" AND 'All_Changes.user'!="*$*" | stats values(All_Changes.result) as "signature",values(All_Changes.src) as "src",values(All_Changes.dest) as "dest", values(All_Changes.user) as "users", DC(All_Changes.user) as user_count by "All_Changes.Account_Management.src_user" | rename "All_Changes.Account_Management.src_user" as "src_user","All_Changes.user" as "user" I am using this query to monitor for Account Deleted- But all the time I am getting this alert triggered for the computer account ending with $ symbol Ex: XYZLAPTOP$ , ABCLAPTOP$ etc I have added the search where 'All_Changes.tag'="delete" AND 'All_Changes.user'!="*$*"" How can I exclude this $ symbol account from the report? Can any one please help
... View more