Understanding Log Sources & Investigating with Splunk - Introduction to Splunk & SPL

EventCode=4624 Account_Name=“-” Account_Name=“-” Account_Name=aparsa | sort - max_login_attempts | stats max(count) as max_login_attempts by Account_Name

Yeah, found additional information but stuck for a long time due to this answer format.
service/protocol → only answer the service without protocol and with capital letter

HTB should added an answer format hint on this question