Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Remove host name in Account_Name field

$
0
0
When people RDP into a server, the results I am getting into splunk is Account_Name=Sever1$ Account_Name = jdoe. When I try to display the data in a table it displays... Account_Name: Server1$ jdoe I want to remove the "Server1$" from field. One thing I will add, is this only happens sometime and not all of the time. Can there be a wildcard to remove anything before the "$".

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>