Hello,
This is my very first post, so corrections are welcomed!
I am looking for a way to add Select/Deselect ALL in splunk Classic or if possible change the delimiter in Studio.
I have a list of ip/emails and i query them as multiselect from a lookup file. My issue is that in studio the delimiter is "," which does not work for me as i need OR/AND. For the classic, i did fixed it, but i have to select each one-by-one.
Is there any fix/workaround for my issues?
Help is much appreciated,
Thank you.
Hi,
Delimiter doesn't work here(.
the option only possible:
index=_internal sourcetype IN ($ms2$)
https://docs.splunk.com/Documentation/Splunk/9.0.3/DashStudio/inputMulti