I wrote a powershell script to query each server for Administrators. The script syslogs the information back to the Alienvault where this plugin picks it up. The Plugin is parsing the data correctly but it is not doing what I was trying to do initially. I am trying to populate the "Users" property under each asset, from what I understood this information is stored in idm_data but the plugin is not populating it... instead everything just goes in acid_event table.
Here is the plugin, I have tried many keywords and username+domain formats, but neither are working.