Hi,
I am trying to create a table but how do I extract these information in my query? I tried double quote " " but it's just looking for exact word.
I want to list out like Subject: Account Name, then Logon Info
Subject:
Security ID: S-1
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Information:
Logon Type: 3
Restricted Admin Mode: -
Virtual Account: No
Elevated Token: No
rmation: Logon Type: 3. I hope it makes sense. Thank you
| rex "Account Name:\s*(?<accountname>\S*)"
| rex "Logon Type:\s*(?<logontype>\S*)"