Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk conditional search on one field

$
0
0
I have events in which Field1 contains multiple values but I only need to look for two values (foo AND bar) and tie them to Field2. What's the most efficient way to craft this search? I'm basically looking for events to be returned in which Field2 has both 'foo' AND 'bar' in Field1 Thx

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>