Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to edit my search to filter out events where the string values between two fields are the same? (field names contain spaces)

$
0
0
Hello, I am trying to filter out events when the source username and destination username are the same, but it is not working when I use the `where` and `NOT field1= field2` function. Is it because I have spaces in the field names? I tried to rename them as different fields and tried the where clause, but it still didn't work. Any help is greatly appreciated. Here is the search: | NOT ("Source User Name"="ANONYMOUS LOGON" OR "Source User Name"=*$) Name!="A user account was changed." | stats dc(Name) as UniqueActionCount, values(Name) as UniqueAction by "Source User Name" | where NOT "Source User Name"="Destination User Name" Thank you.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>