Is there a better way to do an "or" in Splunk?
(api_domain="purchase" OR api_domain="user" OR api_domain="testX")
I assume there is something like api_domain="x" OR "y" OR "z" but Doens't seem to fly.
↧