Splunk Cloud and Enterprise behave differently Isolate access between roles userAccountControl vs. msDS-User-Account-Control-Computed Parse single-line JSON into separate events A guide on using malware-filter lookups Configure regex in field extractor to create relevant fields