Hey, I actually figured it out on my own. For anyone else looking to do something similar:
rule “Windows: Event 4678 Cleanup”
when
has_field(“event_data_Status”) AND contains(to_string($message.event_id), “4768”)
then
//Change Logon Code
let update_source = lookup_value(“winlogon_status_lookup”, $message.event_data_Status);
set_field(“event_data_Status”, update_source);
//Cleanup IP Address
let ip_address = to_string($message.event_data_IpAddress);
set_field(“event_data_IpAddress”,substring(ip_address,7));