Unable to filter Active Directory events based on an underscore in the name on the Active Directory Object when running a Change Auditor Search.
For example, when the following Search criteria is created to filter all Active Directory users with "CA_" in the name more results are retuned than expected:
- On the What tab, Add | Subsystem | Active Directory
- Set "This Object" as the scope
- Enter the like condition: *CA_*
- Save the criteria and run the Search
The expected results are to return any objects that contain "CA_" such as "CA_1", "CA_2", and "CA_3". However, since the underscore is treated like a wildcard, results such as "CA1", "CA2", and "CA3" are also returned.