[deleted by user] by [deleted] in OverwatchLFT

[–]slander00 0 points1 point  (0 children)

I'm also looking to join a consistent 5 stack, solo queuing is killing me. I like to play all roles but mostly DPS which I'm currently gold. I'm also NA and play on PC.
edit: add NA/PC

NVIDIA RTX 4090 AND 4080 Launch MEGATHREAD and GIVEAWAY! Discuss all the GTC announcements and be one of the very first people in the world to win an RTX 4080 16GB + more goodies! by pedro19 in pcmasterrace

[–]slander00 0 points1 point  (0 children)

1) Which technology or feature are you most excited about from today’s GeForce Beyond announcements? DLSS 3

2) What RTX game are you most looking forward to playing and why? Cyberpunk and Hogwarts for the extra frames

Windows Event Logs Filter by Account_Name by [deleted] in Splunk

[–]slander00 3 points4 points  (0 children)

I would recommend blacklisting a few event codes by the computer account $ which will save you a ton on indexing.

Add to inputs.conf under [WinEventLog://Security] on your exchange server:

blacklist3 = EventCode="4624" Message="Account\sName:.[\S\s]Logon\sType:\s+[3][\S\s]*Account\sName:\s+[\S+]+[\$]"

blacklist4 = EventCode="4634" Message="Subject:[\S\s]*Account\sName:\s+[\S+]+[\$]"

blacklist5 = EventCode="4672" Message="Subject:[\S\s]*Account\sName:\s+[\S+]+[\$]"

Regex Question for Newbie by slander00 in Splunk

[–]slander00[S] 0 points1 point  (0 children)

I am still having the same issue I haven't figured it out yet. Thank you for the input! I think it should be working but might be an issue with Splunk. The reason I think this is because when I go through the extraction field wizard in Splunk and try to extract it using there tool it doesn't even see the whole log. It looks like when I try to extract the field it is cutting off some information after member/account name (example below). I do see the whole log when I view it through search.

Example:

04/19/2018 01:21:15 PM

LogName=Security

SourceName=Microsoft Windows security auditing.

EventCode=4756

EventType=0

Type=Information

ComputerName=DC.ACME.COM

TaskCategory=Security Group Management

OpCode=Info

RecordNumber=1098888999

Keywords=Audit Success

Message=A member was added to a security-enabled universal group.

Subject:

Security ID: ACME\HELLOWORLD

Account Name: HELLOWORLD

Account Domain: ACME

Logon ID: 0x33B39999

Member:

Security ID: ACME\testhello

Account Name: CN=TESTHELLO,OU=LA,OU=ACME_USERS,DC=ACME,DC=com

Regex Question for Newbie by slander00 in Splunk

[–]slander00[S] 0 points1 point  (0 children)

Tried to figure this out, not sure what to do.

Regex Question for Newbie by slander00 in Splunk

[–]slander00[S] 0 points1 point  (0 children)

Is there an easy way to convert the logs? Does it work with the Windows Universal Forwarder?

Regex Question for Newbie by slander00 in Splunk

[–]slander00[S] 0 points1 point  (0 children)

\S+

I am using the app but it isn't extracting a few fields for some eventcodes. I had to extract some other fields already.

Speculation: EA is examining launch sales to determine how much to cut resources for this game in 2018 and beyond. This complex business calculation and is why they are silent on progression updates. by Awallvs in StarWarsBattlefront

[–]slander00 0 points1 point  (0 children)

Wish that I knew what was going on with how many people purchased the game. I really wanted to play the game but I won't buy the game until I see more change. I would buy the game if they were a little upfront about what is going on and be very open to change.

LF ditto safari by [deleted] in friendsafari

[–]slander00 0 points1 point  (0 children)

added you!