When people RDP into a server, the results I am getting into splunk is Account_Name=Sever1$ Account_Name = jdoe.
When I try to display the data in a table it displays...
Account_Name:
Server1$
jdoe
I want to remove the "Server1$" from field.
One thing I will add, is this only happens sometime and not all of the time. Can there be a wildcard to remove anything before the "$".
↧