When i search multiple values like (search a OR b OR c OR d OR e) how i can return or display the value which is not coming in the search results
This is the Sentinel Search
problem discussed (with solution) here:
https://conf.splunk.com/session/2015/conf2015-LookupTalk.pdf
@skoelpin is referring to something like this
| appendpipe
[ |stats count(a) as a
| eval empty=if(isnum(a),"0", "a")]
you would have to add the append to for each category a, b, c... etc
if i try to add append for each category i am getting error as Error in 'appendpipe' command: The last argument must be a subsearch.
aaaa@gmail.com | appendpipe [stats count as 1] OR ccc@gmail.com| appendpipe [stats count as 2]
each append needs to be closed by "]". that closes the statement but you have a random OR in there
You will need to do a sub search and append the results onto the first search
Hi, Could you please show me some examples?