probe this: LogParser "SELECT TimeGenerated, EventId,EventTypeName, EventCategoryName, extract_token(strings,10,'|') as UserName, extract_token(strings,2,'|') as File INTO security.txt FROM \\remoteserver\Security WHERE extract_token(string,1,'|') like 'File' and File = 'D:\data\Public\apps\Research...