_time | SubjectUserName | TargetOutboundUserName | host | IpAddress |
Sun Jun 21 08:37:39 2020 | bcharlie | bcharliex | by-100 | ::1 |
Sun Jun 21 08:37:03 2020 | bcharlie | bcharliex | by-100 | ::1 |
I need to exclude search results where SubjectUserName+TargetOutboundUserName will always be excluded.
TargetOutboundUsername will always be SubjectUsername+x
How would I write that out?
Thank you for clarifying the problem. This where clause should do the job.
| where NOT like(TargetOutboundUserName, SubjectUserName."x")
To exclude one or more fields from the results, use the fields command with the '-' option.
| fields - SubjectUserName TargetOutboundUserName
I'm not trying to exclude fields. I'm trying to exclude all events that have
subjectusername + TargetoutboundUsernName+x
bcharlie + bcharliex
kfrog + kfrogx
staceyb + stacebx
I would like those excluded. I think some regex has to be done here?
I mean it won't always be, just when to exclude when the following = true
SubjectUserName + TargetUserName+x
field1
field2=field1+x
field1+(field1+x) -> any time this is true, exclude those events. So fred+cow will show but fred+fredx will be excluded from results.
Thank you for clarifying the problem. This where clause should do the job.
| where NOT like(TargetOutboundUserName, SubjectUserName."x")