How do I filter out TargetUserName or SourceUserName events that contain
'servername$' in those fields [sun or dun]. I'm guessing a regex would
work here but anything I've tried doesn't work, especially in reports.


--
rochfordp
------------------------------------------------------------------------
rochfordp's Profile: https://forums.netiq.com/member.php?userid=6749
View this thread: https://forums.netiq.com/showthread.php?t=54123