I need to filter my Forwarded Events from the Security logs on my domain controllers to only show acutal user accounts and not machine accounts. Using the <Suppress Path> in XML, can I setup a query to exclude all TargetUserName entries that
contain a $? I really only need to keep the log of my users, not each individual computer.
Thanks,
Dave